CVE-2026-28680 | Ghostfolio up to 2.244.x Internal Network Service server-side request forgery (GHSA-hhv6-c34h-pwgh)
A vulnerability was found in Ghostfolio up to 2.244.x. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component Internal Network Service Handler. Performing a manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-28680. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.