Impact
The loadFromJSON method in Fabric.js fails to validate remote URIs, allowing an attacker to supply a crafted JSON payload that causes the server to request arbitrary network resources. This Server‑Side Request Forgery can expose internal endpoints, leak sensitive data, and potentially lead to further exploitation. The defect is identified as CWE‑918.
Affected Systems
Fabric.js library. Any installation that includes loadFromJSON is affected; version details are not disclosed in the advisory, so all current releases that expose this method should be considered vulnerable.
Risk and Exploitability
The CVSS score is 4.0, indicating moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an application to the attack vector is software exploitation via user‑controlled input. Though there are no public exploits reported, the potential for internal network exposure warrants timely mitigation.
OpenCVE Enrichment