PT-2026-68613 · Scripta · Escriptorium

CVE-2026-18359

·

Published

2026-08-06

·

Updated

2026-08-18

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Scripta eScriptorium versions prior to 26.04.2
Description An issue exists in the handling of METS and IIIF import URIs that allows a remote authenticated user to induce the server to send arbitrary HTTP requests to internal hosts, including cloud instance metadata services. This occurs because the IMPORT ALLOWED DOMAINS setting defaults to * and lacks address filtering, redirect caps, or timeouts. The issue is triggered via the mets uri or iiif uri parameters of the 'POST /api/documents/{pk}/imports/' endpoint.
Recommendations Update Scripta eScriptorium to version 26.04.2 or later. Restrict the IMPORT ALLOWED DOMAINS setting to a list of trusted domains instead of using the default wildcard.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18359

Affected Products

Escriptorium