{"id":"CVE-2026-86119","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-86119","summary":"Webstudio through 0.296.0 SSRF via /cgi proxy routes","details":"Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform network reconnaissance on the instance infrastructure.","published":"2026-09-05T09:59:08.747Z","modified":"2026-09-06T03:47:48.845911396Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86119.json"},{"type":"PACKAGE","url":"https://github.com/webstudio-is/webstudio"},{"type":"ARTICLE","url":"https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.asset.$.ts"},{"type":"ARTICLE","url":"https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.image.$.ts"},{"type":"ARTICLE","url":"https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.video.$.ts"},{"type":"REPORT","url":"https://github.com/webstudio-is/webstudio/issues/5816"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86119"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/webstudio-through-0.296.0-ssrf-via-cgi-proxy-routes"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-06T03:47:48.845911396Z"}}