ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. Versions 0.6.7 and below contain a Blind Server-Side Request Forgery (SSRF) vulnerability, in its `/api/ping?url= endpoint`. This allows an attacker to make arbitrary requests to internal or external hosts. This can include discovering ports open on the local machine, hosts on the local network, and ports open on the hosts on the internal network. This issue is fixed in version 0.6.8.
History

Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Thinkdashboard Project
Thinkdashboard Project thinkdashboard
Vendors & Products Thinkdashboard Project
Thinkdashboard Project thinkdashboard

Thu, 06 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Description ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. Versions 0.6.7 and below contain a Blind Server-Side Request Forgery (SSRF) vulnerability, in its `/api/ping?url= endpoint`. This allows an attacker to make arbitrary requests to internal or external hosts. This can include discovering ports open on the local machine, hosts on the local network, and ports open on the hosts on the internal network. This issue is fixed in version 0.6.8.
Title ThinkDashboard: Blind Server-Side Request Forgery (SSRF) vulnerability in /api/ping Endpoint
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-06T21:07:17.672Z

Updated: 2025-11-06T21:29:15.660Z

Reserved: 2025-10-30T17:40:52.028Z

Link: CVE-2025-64327

cve-icon Vulnrichment

Updated: 2025-11-06T21:29:07.420Z

cve-icon NVD

Status : Received

Published: 2025-11-06T21:15:44.117

Modified: 2025-11-06T22:15:44.680

Link: CVE-2025-64327

cve-icon Redhat

No data.