Intel

AIKIDO-2026-694710

vrana/adminer is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)GHSA-77qq-q8fv-x45v Published Yesterday

50

Medium Risk

This Affects:

PHPvrana/adminer
6.0.0 - 6.0.1
Fixed in 6.0.2
Are you affected? Scan for Free

TL;DR

Adminer's ClickHouse driver treats the entire raw HTTP response body from the configured server as the connection error text and displays it without checking that the response actually came from a ClickHouse server. Because the login form lets a visitor supply the server address, this lets that visitor probe arbitrary internal hosts and read their HTTP response content back through the Adminer login error message. The fix limits the printed error to output ClickHouse itself reports as an error.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you have deployed Adminer with the optional ClickHouse driver enabled.

Background info

vrana/adminer is vulnerable to Server-Side Request Forgery (SSRF) in versions 6.0.0 - 6.0.1.

How to fix this

Upgrade the vrana/adminer library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform