THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86119 (HIGH 8.6) — Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instan

[NVD] CVE-2026-86119 (HIGH 8.6) — Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instan

mednvdPublished 2026-09-05

CVE-2026-86119 CVSS: 8.6 HIGH Published: 2026-09-05T10:16:43.157

Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform net

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86119