CVE-2026-33537 | Lychee up to 7.5.0 Photo::fromUrl server-side request forgery (GHSA-vq6w-prpf-h287)
A vulnerability identified as critical has been detected in Lychee up to 7.5.0. This issue affects the function Photo::fromUrl. Performing a manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-33537. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.