HIGH

CVE-2026-18359

Escriptorium Escriptorium 2026-08-06 CVSS v3.1
CVSS
8.5

Description

Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST /api/documents/{pk}/imports/, because the IMPORT_ALLOWED_DOMAINS setting defaults to '*' and no address filtering, redirect cap or timeout is applied

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

0.22%
Probability of exploitation in next 30 days
12.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE