A vulnerability was found in LemmyNet lemmy up to 0.19.17 and classified as critical. Affected by this issue is some unknown functionality of the component Internal Image Handler. The manipulation results in server-side request forgery.

This vulnerability is reported as CVE-2026-42181. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.