Ad

CVE-2026-33537

MEDIUM CVSS 4.0: 5.3 EPSS 0.03%
Updated Apr 01, 2026
Lycheeorg
Parameter Value
CVSS 5.3 (MEDIUM)
Affected Versions before 7.5.1
Fixed In 7.5.1
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Lycheeorg
Public PoC No

Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::fromUrl`) contains an incomplete IP validation check that fails to block loopback addresses and link-local addresses. Prior to version 7.5.1, an authenticated user can still reach internal services using direct IP addresses, bypassing all four protection configuration settings even when they are set to their secure defaults.

Version 7.5.1 contains a fix for the issue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Lycheeorg Lychee
cpe:2.3:a:lycheeorg:lychee:*:*:*:*:*:*:*:*
7.5.1