CVE-2026-51031 is a server-side request forgery vulnerability in FlareSolverr affecting versions prior to 3.4.7. The flaw is present in the /v1 API endpoint and allows a remote attacker to cause the application to issue attacker-influenced server-side requests. By abusing this behavior, an attacker can access or retrieve sensitive information that is reachable from the vulnerable server's network context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit named 'flar3ad' for CVE-2026-51031, targeting FlareSolverr. The repo contains only three files: a GPL license, a README with installation/usage notes, and a single executable Python script that serves as the exploit entry point. The script accepts two arguments: a target FlareSolverr base URL and a file path to read from the remote host. It then builds a JSON payload with cmd='request.get' and url='file://<path>', sets Content-Type: application/json, normalizes the base URL to ensure a trailing slash, and POSTs the payload to the target's /v1 API endpoint. If the target is vulnerable, the response may include the contents of the requested local file. The exploit's main capability is arbitrary file read on the remote server through abuse of FlareSolverr's API handling of file:// URLs. It is not a framework module, does not include persistence or post-exploitation logic, and does not provide a shell or command execution payload. Its purpose is narrowly focused on demonstrating and exploiting remote local-file disclosure via a network-accessible web API.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.