CVE-2026-6625Disclosure

LOWCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the component Picture Storage Service. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-20: 3Active Exploitation · 2026-04-20: 1Technical Details · 2026-04-20: 204-20
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6625 Server-Side Request Forgery in Mogu Blog v2 Picture Storage Service up to 5.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6625

    Post summary

    The entry announces a new Server‑Side Request Forgery vulnerability in Mogu Blog v2’s Picture Storage Service, but provides no exploit code, patch, or evidence of active exploitation.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6625 A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of … https://www.cve.org/CVERecord?id=CVE-2026-6625

    Post summary

    The message announces a newly detected CVE in Migu Blog v2, identifying the affected component and linking to the official CVE record, but provides no exploitation code, patch, or evidence of active attacks.

    0000077
    57.2K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting moxi624 Mogu Blog v2 (CVE-2026-6625) https://vuldb.com/vuln/358260/cti

    Post summary

    CTI team reports widespread activity targeting CVE‑2026‑6625 in Mogu Blog v2, indicating that the flaw is being actively exploited in the wild.

    0000049
    2.1K followersView on X

Explore more