Unauthenticated Server-Side Request Forgery Vulnerability in Webstudio by Webstudio
CVE-2026-86119
9.2CRITICAL
What is CVE-2026-86119?
Webstudio versions up to 0.296.0 contain an unauthenticated server-side request forgery vulnerability that can be exploited through the /cgi/image, /cgi/video, and /cgi/asset proxy routes when the RESIZE_ORIGIN environment variable is not set. This vulnerability allows attackers to provide arbitrary URLs to these endpoints, which may lead to exposure of sensitive cloud instance metadata, unauthorized access to internal services, and facilitate network reconnaissance on the infrastructure.
Affected Version(s)
webstudio 0 <= 0.296.0
