Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.7
Tandoor Recipes Cookmate Import Feature Allows Unauthorized Server Access
CVE-2026-25991
Summary
A security issue in Tandoor Recipes before version 2.5.1 allows anyone who uses the Cookmate import feature to potentially access internal or external websites without permission, which could reveal sensitive information. This affects anyone who uses the Cookmate import feature in Tandoor Recipes. To fix this, update to version 2.5.1 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| tandoor | recipes | <= 2.5.1 | – |
Original title
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerability in the Cookmat...
Original description
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerability in the Cookmate recipe import feature of Tandoor Recipes. The application fails to validate the destination URL after following HTTP redirects, allowing any authenticated user (including standard users without administrative privileges) to force the server to connect to arbitrary internal or external resources. The vulnerability lies in cookbook/integration/cookmate.py, within the Cookmate integration class. This vulnerability can be leveraged to scan internal network ports, access cloud instance metadata (e.g., AWS/GCP Metadata Service), or disclose the server's real IP address. This vulnerability is fixed in 2.5.1.
nvd CVSS3.1
7.7
Vulnerability type
CWE-918
Server-Side Request Forgery (SSRF)
- https://github.com/TandoorRecipes/recipes/commit/fdf22c5e745740db1fec29d6b4bd3df... Patch
- https://github.com/TandoorRecipes/recipes/releases/tag/2.5.1 Product Release Notes
- https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-j6xg-85mh-qqf... Exploit Mitigation Vendor Advisory
Published: 13 Feb 2026 · Updated: 10 Mar 2026 · First seen: 6 Mar 2026