Privoce · Vocechat Server · CVE-2026-100893
**Name of the Vulnerable Software and Affected Versions**
Privoce VoceChat Server versions prior to 0.5.37
**Description**
An issue exists in the `open graphic parse` endpoint within the `open graph::fetch()` function of the `src/api/resource.rs` file. A remote attacker can manipulate the `url` argument to perform server-side request forgery, a technique where the server is coerced into making unauthorized requests to internal or external resources.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `open graphic parse` endpoint to minimize the risk of exploitation.