CVE-2025-60540
Published
CVSS v3
6.5
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS
Description
karakeep v0.26.0 to v0.7.0 was discovered to contain a Server-Side Request Forgery (SSRF).
A self-hostable bookmark-everything app (links, notes and images) with AI-based automatic tagging and full text search