GHSA-474j-x27j-w5wxCriticalCVSS 8.6
Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability...
🔗 CVE IDs covered (1)
📋 Description
Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform network reconnaissance on the instance infrastructure.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-86119
- https://github.com/webstudio-is/webstudio/issues/5816
- https://github.com/webstudio-is/webstudio
- https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.asset.$.ts
- https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.image.$.ts
- https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.video.$.ts
- https://www.vulncheck.com/advisories/webstudio-through-0.296.0-ssrf-via-cgi-proxy-routes
- https://github.com/advisories/GHSA-474j-x27j-w5wx