CVE-2026-5016 | elecV2 elecV2P up to 3.8.3 URL /mock eAxios req server-side request forgery (Issue 202)
A vulnerability categorized as critical has been discovered in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-5016. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.