CVE-2026-92775
OrtaTeknik Veri (Otomatik)
- CVSS Skoru
- 6.5
- EPSS
- —
- CWE
- CWE-918
- KEV Durumu
- Hayır
Wiki.js 2.5.314 sürümüne kadar, Image Prefetch renderer中的 bir sunucu tarafı istek sahteciliği zafiyeti içerir ve bu, protokol, host veya adres doğrulaması olmadan keyfi URL'leri alır. Sayfa düzenleme izinlerine sahip saldırganlar, prefetch-candidate sınıfıyla img öğeleri enjekte ederek sunucunun dahili hizmetleri ve bulut meta veri uç noktalarını istemesini sağlayabilir ve yanıtlar saldırgana döndürülebilir.
Orijinal açıklama (İngilizce)
Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img elements with the prefetch-candidate class to make the server request internal services and cloud metadata endpoints, with responses returned to the attacker.
Referanslar
- https://github.com/geo-chen/oss/blob/main/wiki.md#finding-2-server-side-request-forgery-via-the-image-prefetch-renderer-no-urlhost-validation-on-fetched-image-src
- https://github.com/requarks/wiki
- https://github.com/requarks/wiki/blob/v2.5.314/server/modules/rendering/html-image-prefetch/renderer.js#L1-L21
- https://www.vulncheck.com/advisories/wiki-js-through-2.5.314-server-side-request-forgery-via-image-prefetch
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
