CVE-2026-92775

HIGH CVSS 4.0: 7.1 EPSS 0.30%
Updated Sep 17, 2026
Wiki
Parameter Value
CVSS 7.1 (HIGH)
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Wiki
Public PoC No

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img elements with the prefetch-candidate class to make the server request internal services and cloud metadata endpoints, with responses returned to the attacker.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0