Server-Side Request Forgery in Docs by Suitenumerique
CVE-2026-91081
6.9MEDIUM
What is CVE-2026-91081?
The Docs application from Suitenumerique contains a vulnerability in the cors-proxy endpoint that permits unauthenticated attackers to exploit server-side request forgery. By supplying a public document UUID, adversaries can conduct outbound requests, leveraging DNS time-of-check-to-time-of-use race conditions and shared address space bypasses. This poses a risk of unauthorized access to internal network resources, allowing potential exfiltration of sensitive image content.
Affected Version(s)
docs 0 <= 5.6.1
