{"id":"CVE-2026-86119","summary":"Webstudio through 0.296.0 SSRF via /cgi proxy routes","details":"Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform network reconnaissance on the instance infrastructure.","modified":"2026-09-07T03:45:30.582585931Z","published":"2026-09-05T09:59:08.747Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86119.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86119.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86119"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/webstudio-through-0.296.0-ssrf-via-cgi-proxy-routes"},{"type":"REPORT","url":"https://github.com/webstudio-is/webstudio/issues/5816"},{"type":"PACKAGE","url":"https://github.com/webstudio-is/webstudio"},{"type":"ARTICLE","url":"https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.asset.$.ts"},{"type":"ARTICLE","url":"https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.image.$.ts"},{"type":"ARTICLE","url":"https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.video.$.ts"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/webstudio-is/webstudio","events":[{"introduced":"0"},{"fixed":"631ea0706806b1e8544e03e804c0cf226f20a4c6"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.296.0"},{"fixed":"0.296.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["0.295.0","0.285.1","0.282.1","0.282.0","0.280.0","0.276.0","0.275.0","0.274.3","0.267.0","0.263.0","0.262.1","0.260.2","0.259.0","0.258.0","0.250.0","0.237.0","0.231.0","0.229.0","0.228.0","0.227.0","0.226.0","0.225.0","0.223.0","0.222.0","0.221.0","0.220.0","0.215.0","0.201.0","0.191.5","0.191.4","0.191.3","0.191.2","0.191.1","0.189.0","0.188.0","0.187.0","0.185.0","0.184.0","0.183.0","0.179.0","0.175.0","0.174.0","hello14c4aad82030ae12f83796d84cb894362d6c67bd","0.170.0","0.169.0","0.167.0","0.165.0","0.163.0","0.162.0","0.161.0","0.160.0","0.152.0","0.150.0","0.149.0","0.148.0","0.147.0","0.146.0","0.145.0","0.143.0","0.144.0","0.142.0","0.141.0","0.140.0","0.139.0","0.138.0","0.137.0","0.135.0","0.134.0","0.133.0","0.132.0","0.131.0","0.130.0","ccommit","0.129.0","0.128.0","0.127.0","0.126.0","0.125.0","0.124.0","0.123.0","0.122.0","0.121.0","0.120.0","0.119.0","0.118.0","0.117.0","0.116.0","0.115.0","0.114.0","0.113.0","0.112.0","0.111.0","0.110.0","0.109.0","0.107.0","0.106.0","0.105.0","0.104.0","0.103.0","doff","0.100.0","0.96.0","0.93.0","0.91.0","0.90.0","0.89.0","0.88.0","0.87.1","0.87.0","0.86.0","0.85.0","0.84.0","0.83.0","0.82.0","0.81.0","0.80.0","0.79.0","0.78.0","0.77.0","0.76.0","0.75.0","0.74.0","0.73.0","0.72.0","0.71.0","0.70.0","0.69.0","0.68.0","0.67.0","0.66.0","0.65.0","0.64.0","0.63.0","0.62.0","0.61.0","0.60.0","0.59.0","0.58.0","0.57.0","0.56.0","0.55.3","0.55.2","0.55.1","0.55.0","0.54.0","0.52.0","0.51.1","0.51.0","0.50.0","0.49.0","0.48.0","0.47.0","0.46.0","0.45.0","0.44.0","0.43.0","0.42.0","0.41.0","0.40.0","0.39.0","0.38.0","0.37.0","0.36.0","0.35.0","0.34.0","0.33.0","0.32.0","0.31.0","0.30.0","0.29.0","0.28.0","0.27.0","0.26.0","0.25.0","0.24.0","0.23.0","0.22.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86119.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"}]}