---
id: CVE-2026-86119
title: >-
  Webstudio through 0.296.0 contains an unauthenticated server-side request
  forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy
  routes when RESIZE_ORIGIN environment variable is unset
summary: >-
  Webstudio through 0.296.0 contains an unauthenticated server-side request
  forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy
  routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply
  arbitrary U…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: webstudio-is
product: webstudio
affected:
  - webstudio <= 0.296.0
published: '2026-09-05'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86119'
references:
  - url: 'https://github.com/webstudio-is/webstudio'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.asset.$.ts
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.image.$.ts
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.video.$.ts
    label: disclosure@vulncheck.com
  - url: 'https://github.com/webstudio-is/webstudio/issues/5816'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/webstudio-through-0.296.0-ssrf-via-cgi-proxy-routes
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.0057
epssPercentile: 0.44796
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-18T17:06:17.796062Z'
ingestedAt: '2026-09-06T07:51:56.104Z'
---

## Overview

Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform network reconnaissance on the instance infrastructure.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
