THREAT OPS › Threat News › [NVD] CVE-2026-86119 (HIGH 8.6) — Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instan
[NVD] CVE-2026-86119 (HIGH 8.6) — Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instan
CVE-2026-86119 CVSS: 8.6 HIGH Published: 2026-09-05T10:16:43.157
Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform net
Indicators of compromise
- CVE-2026-86119cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86119