Unauthenticated Server-Side Request Forgery Vulnerability in Webstudio by Webstudio
CVE-2026-86119

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86119?

Webstudio versions up to 0.296.0 contain an unauthenticated server-side request forgery vulnerability that can be exploited through the /cgi/image, /cgi/video, and /cgi/asset proxy routes when the RESIZE_ORIGIN environment variable is not set. This vulnerability allows attackers to provide arbitrary URLs to these endpoints, which may lead to exposure of sensitive cloud instance metadata, unauthorized access to internal services, and facilitate network reconnaissance on the infrastructure.

Affected Version(s)

webstudio 0 <= 0.296.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.