---
id: CVE-2026-92931
title: >-
  CWE-918: Server-Side Request Forgery in the Progress
  @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through
  15.4.8637 may allow a remote attacker to make server-side requests to an
  attacker-controlled host, potentially ex…
summary: >-
  CWE-918: Server-Side Request Forgery in the Progress
  @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through
  15.4.8637 may allow a remote attacker to make server-side requests to an
  attacker-controlled host, potentially ex…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-918
vendor: Progress Software
product: '@progress/sitefinity-nextjs-sdk'
affected:
  - '@progress/sitefinity-nextjs-sdk >= 15.1.8326 < 15.4.8638'
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T14:17:21.323'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92931'
references:
  - url: >-
      https://community.progress.com/s/article/Sitefinity-Critical-Security-Advisory-for-Addressing-Security-Vulnerabilities-in-Next-js-September-2026
    label: security@progress.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T14:21:05.312Z'
---

## Overview

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
