CVE-2026-29178 | LemmyNet Lemmy up to 0.19.15 Query Parameter /api/v4/image/ file_type server-side request forgery (GHSA-jvxv-2jjp-jxc3)
A vulnerability was found in LemmyNet Lemmy up to 0.19.15. It has been classified as critical. This issue affects some unknown processing of the file /api/v4/image/ of the component Query Parameter Handler. The manipulation of the argument file_type leads to server-side request forgery.
This vulnerability is traded as CVE-2026-29178. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.