CVE-2026-25991
Last modified
CVE-2026-25991 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerability in the Cookmate recipe import feature of Tandoor Recipes. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerability in the Cookmate recipe import feature of Tandoor Recipes. The application fails to validate the destination URL after following HTTP redirects, allowing any authenticated user (including standard users without administrative privileges) to force the server to connect to arbitrary internal or external resources. The vulnerability lies in cookbook/integration/cookmate.py, within the Cookmate integration class. This vulnerability can be leveraged to scan internal network ports, access cloud instance metadata (e.g., AWS/GCP Metadata Service), or disclose the server's real IP address. This vulnerability is fixed in 2.5.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tandoor | Recipes | < 2.5.1 |
References
- https://github.com/TandoorRecipes/recipes/releases/tag/2.5.1Product, Release Notes
- https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-j6xg-85mh-qqf7Exploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-25991?
How severe is CVE-2026-25991?
How do I fix CVE-2026-25991?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-25986ImageMagick is free and open-source software used for editin…9.8
- CVE-2026-25987ImageMagick is free and open-source software used for editin…9.1
- CVE-2026-25988ImageMagick is free and open-source software used for editin…7.5
- CVE-2026-25989ImageMagick is free and open-source software used for editin…7.5
- CVE-2026-2599The Database for Contact Form 7, WPforms, Elementor forms pl…9.8
- CVE-2026-25990Pillow is a Python imaging library. From 10.3.0 to before 12…7.5
- CVE-2026-25992SiYuan is a personal knowledge management system. Prior to 3…7.5
- CVE-2026-25993EverShop is a TypeScript-first eCommerce platform. During ca…9.8
- CVE-2026-25994PJSIP is a free and open source multimedia communication lib…9.8
- CVE-2026-25996Inspektor Gadget is a set of tools and framework for data co…9.8
- CVE-2026-25997FreeRDP is a free implementation of the Remote Desktop Proto…9.8
- CVE-2026-25998strongMan is a management interface for strongSwan, an OpenS…7.5
Are you affected by CVE-2026-25991?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
