rootpwn

high · CVSS v3 6.5 · CVSS v4 7.1

CVE-2026-92775

A server-side request forgery (SSRF) vulnerability exists in Wiki.js versions up to 2.5.314 within its Image Prefetch renderer component. Th

Overview

A server-side request forgery (SSRF) vulnerability exists in Wiki.js versions up to 2.5.314 within its Image Prefetch renderer component. The application fails to validate protocol, host, or network addresses when fetching external image resources during prefetching. Authenticated users with page editing privileges can leverage this weakness to cause the server to perform HTTP requests to internal services and cloud metadata endpoints.

Description

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img elements with the prefetch-candidate class to make the server request internal services and cloud metadata endpoints, with responses returned to the attacker.

Impact

Impacts organizations deploying Wiki.js on internal networks or in cloud environments. Successful exploitation compromised Confidentiality by exposing responses from internal network endpoints and cloud service metadata to authenticated editors, potentially compromising Integrity and Availability depending on accessible internal interfaces.

Remediation

Upgrade Wiki.js to a version higher than 2.5.314 where SSRF protections are implemented. Implement strict egress filtering on the server hosting Wiki.js to block requests to RFC 1918 private address spaces and cloud instance metadata service IPs (e.g., 169.254.169.254). Audit and limit page editing privileges to trusted accounts.

Risk context

The vulnerability carries a High severity rating (CVSS v3: 6.5, CVSS v4: 7.1) with no current EPSS score available. While attack execution requires authenticated page editing permissions, the threat to cloud metadata endpoints warrants immediate review for cloud-hosted environments.

Affected products

  • Requarks Wiki.js <= 2.5.314

Scores

Severity
high
CVSS v2
6.8
CVSS v3
6.5
CVSS v4
7.1
EPSS

Wiki.js SSRF CVE-2026-92775 Access Control Cloud Security Patch Management

← All CVEs