Vulnerability Description
Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the game export API. The players parameter is passed directly to an internal HTTP client without validation, allowing remote attackers to force the server to send HTTP requests to arbitrary URLs
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lichess | Lila | < 2025-06-02 |
Related Weaknesses (CWE)
References
- https://github.com/lichess-org/lila/commit/11b4c0fb00f0ffd8232346f839627005459c8Broken Link
- https://hackerone.com/reports/3165242ExploitIssue Tracking
FAQ
What is CVE-2025-52186?
CVE-2025-52186 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the game export API. The players parameter is passed dir...
How severe is CVE-2025-52186?
CVE-2025-52186 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-52186?
Check the references section above for vendor advisories and patch information. Affected products include: Lichess Lila.