PT-2026-94072 · Coze Dev+1 · Coze-Studio

·

CVE-2026-92795

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Coze Studio versions prior to 0.5.2
Description Authenticated users can exploit a lack of restriction on the server URL provided during the registration of plugin tools. This allows the backend to fetch internal services, enabling attackers to construct requests that access cloud metadata endpoints and other internal services reachable only from the backend network to retrieve sensitive information.
Recommendations Update Coze Studio to version 0.5.2 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92795

Affected Products

Coze-Studio