CVE-2026-3958Disclosure

LOWCVSS 2.1 · LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability has been found in Woahai321 ListSync up to 0.6.6. This issue affects the function requests.post of the file list-sync-main/api_server.py of the component JSON Handler. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-16)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-11: 1Mentions · 2026-06-16: 2PoC Mentioned / Linked · 2026-06-16: 2Technical Details · 2026-03-11: 1Technical Details · 2026-06-16: 203-1106-16
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-06-162
Disclosure1PoC1
Full discourse3 posts
  • Geng Yang@geng_zast
    PoC

    ListSync is an OSS tool that syncs IMDb and Trakt watchlists into Overseerr and Jellyseerr. The public report for CVE-2026-3958 shows the issue with an OOB callback and a minimal payload: https://github.com/Woahai321/list-sync/issues/79 @fofabot @zoomeye_team @HunterMapping @ExploitDB @oss_security @OpenSecurity_IN

    Post summary

    The post shares a minimal proof‑of‑concept payload for CVE‑2026‑3958 via a GitHub link, indicating the vulnerability was publicly reported but does not mention active exploitation or patches.

    1000079
    49 followersView on X
  • ZAST AI@zast_ai
    Disclosure

    Security note: CVE-2026-3958 affects ListSync, an OSS project. http://ZAST.AI verified that its Discord test-notification path can be driven into SSRF when request data controls the destination. https://t.co/cOINYqkcZr

    Post summary

    The note reports that CVE‑2026‑3958 in ListSync enables SSRF via a Discord test‑notification path, with a verified proof of concept link, but no patch, exploit code, or active exploitation evidence is provided.

    1000059
    37 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3958 A vulnerability has been found in Woahai321 ListSync up to 0.6.6. This issue affects the function http://requests.post of the file list-sync-main/api_server.py of the componen… https://www.cve.org/CVERecord?id=CVE-2026-3958

    Post summary

    The post announces CVE‑2026‑3958 in Woahai321 ListSync affecting the requests.post function in api_server.py; it provides component details but no PoC, exploit, or patch information.

    00000118
    56.7K followersView on X

Explore more