LOW
go-sonic
CVE published 2026-01-01
CVE-2025-15414
A server-side request forgery vulnerability exists in go-sonic sonic up to 1.1.4, specifically in the FetchTheme function of the service/theme/git_fetcher.go file. This flaw allows remote attackers to manipulate the uri argument, potentially leading to unauthorized requests. The exploit has been published, and although the vendor was notified, no response was received.