Impact
A cache poisoning flaw exists in CoreBunch Instatic up to version 0.0.14. The vulnerability is triggered by crafting the u query parameter of the GET /_instatic/hole/<nodeId> server island endpoint. Because the origin page URL supplied in u is used to seed the route template for rendering and the response is stored in a shared cache keyed solely by nodeId, an attacker can inject a malicious route. All users that later request the same nodeId will be served the attacker‑controlled fragment, resulting in malformed or malicious content delivered to the browser.
Affected Systems
The affected product is CoreBunch Instatic. All releases through 0.0.14 are vulnerable. Users running these versions are at risk, while versions following the remediation patch address the issue. The vulnerability applies to the server island feature that exposes the /_instatic/hole/<nodeId> endpoint.
Risk and Exploitability
The CVSS score of 6.1 classifies the flaw as medium severity, and the EPSS score is not available. The vulnerability is exploitable by any remote user without authentication via a standard HTTP request. No exploit has been reported in CISA KEV. The lack of an EPSS value means the probability of exploitation is unknown, but the remote nature and lack of authentication increase the attack surface. Organizations should treat it as a moderate risk until a patch is applied.
OpenCVE Enrichment