CVE-2026-19352Disclosure

LOWCVSS 1.3 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack requires access to the local network. This attack is characterized by high complexity. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized. This patch is called 260802348955231442c4bae6c2d9d8ede947af0a. It is best practice to apply a patch to resolve this issue. The project maintainer provides this view: "I'm not sure that this is a critical vulnerability, because it is behind an experimental CLI flag and the NTLM behavior isn't really a LosslessCut bug." The CVSS vector reflects the high level of pre-requisites.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-08-09)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-08: 1Mentions · 2026-08-09: 2Technical Details · 2026-08-08: 108-0808-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-081
Disclosure1
2026-08-092
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19352 A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the compo… https://www.cve.org/CVERecord?id=CVE-2026-19352 ----- Traducción: CVE-2026-19352 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-19352 affecting mifi lossless‑cut up to 3.69.0, noting a vulnerability in httpServer.ts, but provides no further details on exploitation, patching, or technical depth.

    0000032
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19352 A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the compo… https://www.cve.org/CVERecord?id=CVE-2026-19352

    Post summary

    The text reports a new vulnerability (CVE‑2026‑19352) affecting mifi lossless‑cut up to version 3.69.0, pointing to an unidentified issue in src/main/httpServer.ts, with no exploit, patch, or PoC details provided.

    000001.3K
    57.9K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🎬 LosslessCut built-in API vulnerable to SSRF CVE-2026-19352 affects LosslessCut through 3.69.0. Its built-in HTTP API contains a server-side request forgery (SSRF) weakness that may allow unintended requests toward other systems or internal services. 📅 Disclosed: August 8. 🔎 Source: CVE/Vulnerability feed via YANAC. #SSRF #LosslessCut #CVE #CyberSecurity #AppSec

    Post summary

    The announcement reveals a newly disclosed SSRF vulnerability (CVE‑2026‑19352) in LosslessCut’s built‑in API, with technical details but no PoC, exploit code, active use, or patch information provided.

    0000041
    34 followersView on X

Explore more