Exploit for CVE-2026-28680

Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. This issue has been patched in version 2.245.0.

Published: 2026-03-06

CVSS: 9.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

Download Exploit for CVE-2026-28680 here:

Use Tor Browser to access .onion site.

https://sonitex.com/exploit-602-cve-2026-29183/

https://sonitex.com/exploit-503-cve-2025-69338/