A server-side request forgery (SSRF) vulnerability has been identified in the light0011 CMS project. The flaw exists in the catchimage function within the file Public/ueditor/php/controller.php, part of the UEditor component. An attacker can manipulate the source[] argument to trigger SSRF attacks remotely. The exploit has been publicly disclosed and is available for use in attacks. The affected product uses a rolling release model, so no specific version information is available. The project maintainer was notified via an issue report but has not yet responded. This represents an unpatched, publicly exploitable vulnerability with elevated risk due to lack of vendor response.