PT-2026-94072 · Coze Dev+1 · Coze-Studio
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Coze Studio versions prior to 0.5.2
Description
Authenticated users can exploit a lack of restriction on the server URL provided during the registration of plugin tools. This allows the backend to fetch internal services, enabling attackers to construct requests that access cloud metadata endpoints and other internal services reachable only from the backend network to retrieve sensitive information.
Recommendations
Update Coze Studio to version 0.5.2 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coze-Studio