Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-59702

repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack
Back to all
CVE

CVE-2026-59702

repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack

repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file:// URLs before passing them to git clone, enabling attackers to access private network addresses, GCP metadata services, or local filesystem paths.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.2
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59702.json, https://nvd.nist.gov/vuln/detail/CVE-2026-59702, https://www.vulncheck.com/advisories/repomix-server-side-request-forgery-via-unvalidated-repository-urls-in-post-api-pack, https://github.com/yamadashy/repomix/issues/1703, https://github.com/CrazyForks/repomix/commit/c748b524f41225e7fc6f89ad0084520901a453cf, https://github.com/yamadashy/repomix

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.00324%
EPSS Percentile
0.25418%
Introduced Version
0
Fix Available
c748b524f41225e7fc6f89ad0084520901a453cf,a7b93adfcdb11be923a9a092cceb1cb6739ef8e1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading