LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3286 - Vulnerability Analysis

MediumCVSS: 6.3

Last Updated: March 2, 2026

itwanger paicoding - Server-Side Request Forgery

Published: February 27, 2026Updated: March 2, 2026PoC AvailableRemote Exploitable

Overview

itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3 contains a server-side request forgery caused by manipulation of the "img" argument in Image Save Endpoint, letting remote attackers make arbitrary server requests, exploit requires no special privileges.

Severity & Score

Severity: Medium
CVSS Score: 6.3

Impact

Remote attackers can make arbitrary server requests, potentially accessing internal resources or causing further attacks.

Mitigation

Update to the latest version or apply vendor patches when available.

Details

CVE ID
CVE-2026-3286
Severity
Medium
CVSS Score
6.3
Type
server_side_request_forgery
Status
confirmed

CWE

  • CWE-918

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L