Server-Side Request Forgery Vulnerability in Privoce VoceChat Server
CVE-2026-100893
Key Information:
- Vendor
Privoce
- Status
- Vendor
- CVE Published:
- 28 September 2026
Badges
What is CVE-2026-100893?
A security flaw has been identified in the Privoce VoceChat Server, specifically impacting the open_graph::fetch function within the src/api/resource.rs component. This vulnerability allows an attacker to manipulate the 'url' argument, potentially leading to server-side request forgery. The exploit can be executed remotely, creating a significant risk for systems running affected versions up to 0.5.36. Despite early communication regarding this vulnerability, there has been no response from the vendor, raising concerns about the security of their product.
Affected Version(s)
VoceChat Server 0.5.0
VoceChat Server 0.5.1
VoceChat Server 0.5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
