{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awebstudiowebstudio/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:webstudio:webstudio:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-86119"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Webstudio (\u003c= 0.296.0)"],"_cs_severities":["high"],"_cs_tags":["webstudio","ssrf","vulnerability","cloud-security"],"_cs_type":"advisory","_cs_vendors":["Webstudio"],"content_html":"\u003cp\u003eWebstudio through version 0.296.0 contains an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The flaw exists within the /cgi/image, /cgi/video, and /cgi/asset proxy routes when the RESIZE_ORIGIN environment variable is left unset. Because these endpoints do not properly validate user-supplied URLs before performing a request, an unauthenticated remote attacker can force the application to make arbitrary outbound HTTP requests from the server's context.\u003c/p\u003e\n\u003cp\u003eThis vulnerability allows attackers to bypass network perimeters to access sensitive cloud instance metadata (e.g., AWS IMDS or GCP metadata services), interact with internal services that are not exposed to the internet, and conduct network reconnaissance of the host infrastructure. Defenders should ensure the RESIZE_ORIGIN environment variable is properly configured or upgrade to a patched version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the exfiltration of sensitive cloud provider credentials via metadata services, unauthorized access to internal management interfaces, and infrastructure-wide network mapping. This poses a high risk to organizations hosting Webstudio in cloud environments where instance metadata is accessible.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure the RESIZE_ORIGIN environment variable is set to a restricted, known-good value to disable the vulnerable proxy behavior.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous requests to /cgi/ endpoints that contain suspicious URL query parameters or private IP addresses.\u003c/li\u003e\n\u003cli\u003eRestrict outbound network access from the Webstudio server to the cloud metadata service IP address (e.g., 169.254.169.254) using host-based firewalls or cloud security groups.\u003c/li\u003e\n\u003cli\u003eApply patches or updates from the vendor as soon as they are released to address the underlying input validation flaw in the proxy routes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T13:31:57Z","date_published":"2026-09-05T13:31:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-webstudio-ssrf/","summary":"Webstudio versions through 0.296.0 are vulnerable to unauthenticated SSRF via proxy endpoints, allowing attackers to access internal cloud metadata and services.","title":"Unauthenticated SSRF Vulnerability in Webstudio","url":"https://feed.craftedsignal.io/briefs/2026-09-webstudio-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:webstudio:webstudio:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}