CVE-2025-27344

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 24, 2025
CWE ID 352

Summary

CVE-2025-27344 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Phee's LinkPreview from versions n/a through 1.6.7. An attacker can exploit this issue to make unauthorized requests on behalf of an unsuspecting user. The attack requires the attacker to trick the user into visiting a malicious website, which then executes a malicious request on the affected LinkPreview application. This vulnerability poses a significant risk to user privacy and security. It is recommended that users update to the latest version of LinkPreview to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share