CVE-2025-61768 Details
Description
KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists in the Media module of the Kuno CMS administrative panel. A logged-in administrator can upload a specially crafted SVG file containing an external image reference, causing the server to initiate an outgoing connection to an arbitrary external URL. This can lead to information disclosure or internal network probing. Version 1.3.15 contains a fix for the issue.
A server-side request forgery (SSRF) vulnerability has been identified in the Media module of KUNO CMS, prior to version 1.3.15. This vulnerability allows a logged-in administrator to upload a specially crafted SVG file that references an external image. When the server processes this SVG, it follows the reference and makes an outgoing request to the specified URL. This could lead to information disclosure or internal network probing.
Users should update to KUNO CMS version 1.3.15 or later, where this vulnerability has been fixed. Instructions for updating can be found in the KUNO CMS release notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 6, 2025CISA-ADP
Assessed Oct 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/xuemian168/kuno/commit/804b2909c65b16ae2063d0f992e0711aa09475e2 | [email protected] | Source CodeVendor |
| https://github.com/xuemian168/kuno/releases/tag/v1.3.15 | [email protected] | Release NotesVendor |
| https://github.com/xuemian168/kuno/security/advisories/GHSA-4f5f-2c49-5mwm | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| KUNO CMS | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 6, 2025 | New CVE Received | [email protected] |
Volerion