PT-2026-94053 · Requarks+1 · Wiki.Js+1

·

CVE-2026-92775

·

Published

2026-09-16

·

Updated

2026-09-21

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wiki.js versions prior to 2.5.315
Description The Image Prefetch renderer allows server-side request forgery, a flaw where the server is tricked into making requests to an unintended location. This occurs because the renderer fetches arbitrary URLs without validating the protocol, host, or address. Users with page editing permissions can inject img elements using the prefetch-candidate class to force the server to request internal services or cloud metadata endpoints, with the resulting responses being returned to the attacker.
Recommendations Update Wiki.js to version 2.5.315 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92775

Affected Products

Wiki.Js
Wiki