Server-side request forgery in mealie-recipes Mealie Recipe Action Trigger

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-94028?

CVE-2026-94028 is a vulnerability classified as Server-Side Request Forgery (SSRF), affecting Mealie (affected versions: 3.25.0 and 3.25.1). This vulnerability is rated Medium, with a CVSS score of 5.3. Public exploit code or evidence is available for this vulnerability, but that does not confirm exploitation in the wild.

Overview

Original source data

A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.26.0 is able to address this issue. This patch is called fb221afa258c8dd2c4ac95b1996c33ef9db3f477. The affected component should be upgraded.

Affected products and scope

  • mealie-recipes Mealie, Recipe Action Trigger: versions 3.25.0 and 3.25.1 are explicitly listed as affected.
  • The source description defines the affected scope as Mealie through version 3.25.1.
  • Version 3.26.0 is identified as the fixing release. The available evidence does not establish the status of parallel branches or every later release, so a broader open-ended range should not be inferred.

Technical details

The flaw affects the Recipe Action Trigger component, specifically payload.model_dump in mealie/routes/households/controller_group_recipe_actions.py. A user-controlled url value reaches the server-side HTTP request path. The maintainer report states that the existing validator checks only for an http or https scheme, without checking private, loopback, link-local, metadata, or allowlisted destinations, and that this path bypasses the existing SSRF-protected transport. As a result, the Mealie server can send HTTP POST requests to unintended destinations, including internal services or systems reachable from the server network. The attack requires an authenticated Mealie account but does not require administrator privileges according to the technical report. The response from the destination is discarded by the background task, so direct data retrieval through the application response depends on the target service; the record does not establish one universal outcome across deployments.

Exploitability

Reachability: The issue is remotely reachable through Mealie's Recipe Action Trigger functionality.

Authentication: An authenticated Mealie user is required. The technical report states that an ordinary user, without administrator privileges, is sufficient.

Complexity and interaction: The record describes the attack as low complexity and requiring no interaction from another user. The attacker must still be able to create and trigger a recipe action.

Exploitation status: The record states that an exploit has been made public, and the maintainer issue contains a proof of concept. The supplied evidence does not confirm exploitation in the wild, a specific campaign, or a specific victim.

Technical impact

The flaw lets an authenticated user control the destination of an HTTP request initiated by the Mealie server, extending the attacker's reach into networks accessible to that server. The primary technical consequence is possible disclosure from internal services or cloud metadata; in some environments, retrieved information could support further access to other resources. Sending POST requests to internal services may also cause state changes when the target accepts them, but the record does not prove that outcome. The issue does not by itself establish code execution in Mealie, and the practical impact is constrained by network reachability, authentication, and the logic of the target service.

Business impact

An authenticated Mealie account can use the application server as a network vantage point to reach systems that the account cannot access directly. Depending on the deployment, this may expose internal administrative services, cloud metadata, or temporary credentials made available by a metadata service. Internal services that accept HTTP POST requests could also perform changes if the request satisfies their own requirements, but the record does not confirm successful state changes. Actual impact depends on the Mealie server's network access and how destination services process the request.

Remediation

  1. Upgrade Mealie to exactly version 3.26.0, which the record identifies as addressing the issue. Do not automatically interpret this evidence as verification of every later or parallel release branch.
  2. If an upgrade cannot be completed immediately, apply network-level egress controls that block unnecessary access from Mealie to private, loopback, link-local, reserved, and cloud metadata ranges. This reduces exposure but does not replace the update.
  3. Restrict creation and triggering of Recipe Action Trigger entries to trusted users, and review and remove existing actions that point to internal or unapproved destinations.
  4. After updating, recheck outbound HTTP configuration and monitor for unexpected requests from Mealie to confirm that the defensive controls are working as intended.

Detection

  1. Inventory deployed Mealie versions and identify systems that enable or use Recipe Action Trigger. Treat the versions listed as affected as exposed until upgraded.
  2. Review existing recipe action configurations, especially url values pointing to 127.0.0.1, 169.254.169.254, private networks, loopback, link-local, metadata services, or unexpected internal hostnames.
  3. Review access logs for recipe action creation and trigger operations by unexpected accounts, as well as unusual use of this functionality.
  4. Review network telemetry from Mealie servers for HTTP POST requests to private, reserved, link-local, or cloud metadata destinations. This is precautionary monitoring, not a confirmed indicator of compromise.
  5. The absence of matching log evidence does not prove safety because the request runs in a background task and the response is discarded.
Sources (20)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan