PatchSiren

go-sonic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW go-sonic CVE published 2026-01-01

CVE-2025-15414

A server-side request forgery vulnerability exists in go-sonic sonic up to 1.1.4, specifically in the FetchTheme function of the service/theme/git_fetcher.go file. This flaw allows remote attackers to manipulate the uri argument, potentially leading to unauthorized requests. The exploit has been published, and although the vendor was notified, no response was received.