Executive brief
wallabag is a self-hosted web application that allows users to save and organize articles for later reading. A vulnerability in the PDF export feature allows attackers to craft malicious article titles or content that can be exploited to perform Server-Side Request Forgery (SSRF) attacks, potentially enabling unauthorized access to internal network resources or services running on the affected server.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) flaw in the PDF export functionality of wallabag versions 2 through 2.6.14. The vulnerability exists because user-controlled title and content fields are mishandled during PDF generation, allowing an attacker to inject malicious content that causes the server to make unintended requests to arbitrary URLs or internal network resources. The attack vector is network-based and does not require authentication beyond normal user access to the wallabag instance. An attacker with the ability to add articles (or modify existing ones) can exploit this to probe internal networks, access local services, or retrieve sensitive information from internal systems. Patches are expected to be available in versions after 2.6.14.
Affected products
- wallabag wallabag 2 through 2.6.14
Timeline
- 2026-08-28: disclosed
- other: Reported to maintainers via GitHub Private Security Advisory on June 5, 2026