mediumCVSS 6.5Vulnerability

GHSA-ggxf-37hm-9wqf

instagrapi versions before 2.6.9 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the paths were relative Instagram API paths. A malicious or tampered challenge payload could cause challenge handling requests to be sent outside the intended Instagram host with the client\'s existing session headers. Version 2.6.9 validates challenge paths before building URLs, solving captcha challenges, or submitting phone/SMS challenge forms.

Properties

ghsa_id
GHSA-ggxf-37hm-9wqf
severity
medium
summary
instagrapi: Unsafe signup challenge path handling in instagrapi
cvss_score
6.5
cve_id
GHSA-ggxf-37hm-9wqf
cvss_vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-05-23T00:12:34Z
source_url
https://github.com/advisories/GHSA-ggxf-37hm-9wqf
ghsa_updated
2026-05-23T00:12:34Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]pip/instagrapi

AFFECTS (1)

[Software]pip/instagrapi

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph