← Vulnerability feed

Vulnerability record · CVE-2023-32750 · published 8 June 2023

CVE-2023-32750: Pydio cells server-side request forgery (ssrf) vulnerability

Pydio · Cells

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

6.5 CVSS 3.1 Medium EPSS 3.8% · top 10.2% CWE-918 · Server-side request forgery (SSRF)
6.5CVSS 3.1 base score
3.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-32750 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-32749Pydio cells incorrect authorization vulnerabilityPydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when cre…EPSS 14%8.8CVE-2019-12901Pydio cells path traversal vulnerabilityPydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders…EPSS 1.7%8.1CVE-2020-12851Pydio cells path traversal vulnerabilityPydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by up…EPSS 1.5%7.2CVE-2020-12847Pydio cells vulnerabilityPydio Cells 2.0.4 web application offers an administrative console named “Cells Console” that is available to users with an administrator role. This …EPSS 1.7%7.0CVE-2020-12850Pydio cells improper privilege management vulnerabilityThe following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as v…EPSS 0.49%6.8CVE-2020-12852Pydio cells improper input validation vulnerabilityThe update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the download…EPSS 2.4%6.5CVE-2021-41324Pydio cells path traversal vulnerabilityDirectory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cel…EPSS 2.1%6.5CVE-2021-41323Pydio cells path traversal vulnerabilityDirectory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells files belong…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2023-32750), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.