Vulnerability Description
Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform network reconnaissance on the instance infrastructure.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/webstudio-is/webstudio
- https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1
- https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1
- https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1
- https://github.com/webstudio-is/webstudio/issues/5816
- https://www.vulncheck.com/advisories/webstudio-through-0.296.0-ssrf-via-cgi-prox
FAQ
What is CVE-2026-86119?
CVE-2026-86119 is a vulnerability with a CVSS score of 8.6 (HIGH). Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is un...
How severe is CVE-2026-86119?
CVE-2026-86119 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-86119?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.