---
id: CVE-2025-69206
title: >-
  Hemmelig is a messing app with with client-side encryption and
  self-destructing messages
summary: >-
  Hemmelig is a messing app with with client-side encryption and
  self-destructing messages. Prior to version 7.3.3, a Server-Side Request
  Forgery (SSRF) filter bypass vulnerability exists in the webhook URL
  validation of the Secret Request…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-918
vendor: hemmelig
product: hemmelig
affected:
  - hemmelig < 7.3.3
patched:
  - hemmelig 7.3.3
published: '2025-12-29'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:10:00.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-69206'
references:
  - url: >-
      https://github.com/HemmeligOrg/Hemmelig.app/commit/6c909e571d0797ee3bbd2c72e4eb767b57378228
    label: security-advisories@github.com
  - url: >-
      https://github.com/HemmeligOrg/Hemmelig.app/security/advisories/GHSA-vvxf-wj5w-6gj5
    label: security-advisories@github.com
  - url: >-
      https://github.com/HemmeligOrg/Hemmelig.app/security/advisories/GHSA-vvxf-wj5w-6gj5
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00203
epssPercentile: 0.09264
ingestedAt: '2026-10-05T19:30:59.956Z'
---

## Overview

Hemmelig is a messing app with with client-side encryption and self-destructing messages. Prior to version 7.3.3, a Server-Side Request Forgery (SSRF) filter bypass vulnerability exists in the webhook URL validation of the Secret Requests feature. The application attempts to block internal/private IP addresses but can be bypassed using DNS rebinding or open redirect services. This allows an authenticated user to make the server initiate HTTP requests to internal network resources. Version 7.3.3 contains a patch for the issue.

## Affected

- `hemmelig < 7.3.3`

## Remediation

Upgrade past the affected range:

- `hemmelig 7.3.3`
