A vulnerability marked as critical has been reported in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component Product Upload Endpoint. Performing a manipulation of the argument params.url results in server-side request forgery.

This vulnerability is reported as CVE-2026-19927. The attack is possible to be carried out remotely. Moreover, an exploit is present.

It is suggested to upgrade the affected component.