CVE-2026-3286 - Vulnerability Analysis
MediumCVSS: 6.3Last Updated: March 2, 2026
itwanger paicoding - Server-Side Request Forgery
Published: February 27, 2026Updated: March 2, 2026PoC AvailableRemote Exploitable
Overview
itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3 contains a server-side request forgery caused by manipulation of the "img" argument in Image Save Endpoint, letting remote attackers make arbitrary server requests, exploit requires no special privileges.
Severity & Score
Severity: Medium
CVSS Score: 6.3
Impact
Remote attackers can make arbitrary server requests, potentially accessing internal resources or causing further attacks.
Mitigation
Update to the latest version or apply vendor patches when available.
References
Related Resources
Details
- CVE ID
- CVE-2026-3286
- Severity
- Medium
- CVSS Score
- 6.3
- Type
- server_side_request_forgery
- Status
- confirmed
CWE
- CWE-918
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L