ROSECURIFY
~/ advisories/ RO-26-001

Mailpit - Server-Side Request Forgery (SSRF)

axllent vendorMailpit product< 1.28.0 version

Overview #

A Server-Side Request Forgery (SSRF) vulnerability exists in Mailpit's /proxy endpoint that allows attackers to make requests to internal network resources.

Vulnerability Details #

Affected Versions: < 1.28.0

Location: /api/v1/proxy endpoint

Affected Parameter: url

Root Cause: The vulnerability exists due to insufficient validation of user-supplied URLs. Attackers can supply internal URLs that the server will fetch on their behalf.

Exploitation Requirements #

Impact #

Remote attackers can exploit this vulnerability to:

Proof of Concept #

http
GET /api/v1/proxy?url=http://169.254.169.254/latest/meta-data/ HTTP/1.1
Host: mailpit.target.com

Solution #

Upgrade to Mailpit version 1.28.1 or later, which includes proper URL validation for the proxy endpoint.

References #

Timeline #

Credits: Omar Kurt