Unauthenticated SSRF via unchecked repository URLs
Published Jul 8, 2026 · Updated Jul 8, 2026
SSRF in yamadashy Repomix before 1.14.1 allows remote attackers to trigger server-side requests through POST /api/pack. The parseRemoteValue path accepts http://, https://, and file:// repository URLs after checking only an owner/repository shape, then processRemoteRepo passes the reconstructed URL to git clone without a public-host allowlist. Self-hosted or development deployments without the origin secret or Turnstile key are directly reachable; successful requests can probe internal services or access local Git repositories, while response bodies are not normally returned.
Summary
What happened
SSRF in yamadashy Repomix before 1.14.1 allows remote attackers to trigger server-side requests through POST /api/pack. The parseRemoteValue path accepts http://, https://, and file:// repository URLs after checking only an owner/repository shape, then processRemoteRepo passes the reconstructed URL to git clone without a public-host allowlist. Self-hosted or development deployments without the origin secret or Turnstile key are directly reachable; successful requests can probe internal services or access local Git repositories, while response bodies are not normally returned.
The record
- CVE
- CVE-2026-59702
- Published
- Jul 8, 2026
- Updated
- Jul 8, 2026
- Vendor
- yamadashy
- Product
- Repomix
- Classifications
- CWE-918, CAPEC-664, T1190
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jul 8, 2026CVE publishedPublication date reported by the CVE source.
- Jul 8, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <1.14.1
- Affected versionversion=0 <=c748b52
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Repomix POST /api/pack SSRF proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo