MEDIUM
CVE-2026-92775
CVSS
6.5
Description
Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img elements with the prefetch-candidate class to make the server request internal services and cloud metadata endpoints, with responses returned to the attacker.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
0.3%
Probability of exploitation in next 30 days
23.3th percentile
References
https://github.com/geo-chen/oss/blob/main/wiki.md#finding-2-server-side-request-forgery-via-the-image-prefetch-renderer-no-urlhost-validation-on-fetched-image-src
https://github.com/requarks/wiki
https://github.com/requarks/wiki/blob/v2.5.314/server/modules/rendering/html-image-prefetch/renderer.js#L1-L21
https://www.vulncheck.com/advisories/wiki-js-through-2.5.314-server-side-request-forgery-via-image-prefetch
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.