CVE-2026-5618 Details
Description
A vulnerability was detected in kalcaddle kodbox up to 1.64. This affects an unknown function of the component shareMake/shareCheck. Performing a manipulation of the argument siteFrom/siteTo results in server-side request forgery. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A server-side request forgery (SSRF) vulnerability has been identified in Kalacaddle Kodbox versions through 1.64. The issue arises in the share management component, specifically within the shareMake and shareCheck functions. The vulnerability allows remote attackers to manipulate the siteFrom and siteTo parameters, coercing the server into making HTTP requests to arbitrary internal or external URLs. This could potentially access sensitive resources or internal services only reachable from the server's network. The vulnerability exploits a hard-coded cryptographic key used for token validation, enabling unauthorized modifications of share configurations, including those targeting high-privilege users such as admins.
Users are advised to update to a version of Kodbox that addresses this vulnerability. For those unable to update, it is recommended to remove the hard-coded 'kodShareOut' key from the share management endpoint and implement proper authentication and authorization checks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 6, 2026CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/submit/785572 | [email protected] | Technical Description |
| https://vuldb.com/vuln/355408 | [email protected] | AdvisoryBundleExploitPartial Content |
| https://vuldb.com/vuln/355408/cti | [email protected] | |
| https://vulnplus-note.wetolink.com/share/3VtzyzYgcS4b | [email protected] | ExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kalcaddle kodbox | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 6, 2026 | New CVE Received | [email protected] |
Volerion