Impact
Webstudio versions through 0.296.0 contain an unauthenticated SSRF vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when the RESIZE_ORIGIN environment variable is unset. Attackers may supply arbitrary URLs to these endpoints, causing the server to retrieve the target resource and allowing read access to cloud instance metadata, probing internal services, and performing network reconnaissance on the instance infrastructure. This flaw permits the attacker to reach destinations beyond the intended external interface, exposing confidential data and internal network topology.
Affected Systems
The affected product is Webstudio from the vendor Webstudio. All releases up to and including version 0.296.0 are vulnerable. Any deployment of 0.296.0 or earlier carries the risk.
Risk and Exploitability
The flaw earns a CVSS score of 9.2, indicating critical severity, and the EPSS score is not available. It is not listed in the CISA KEV catalog. Attackers can exploit the issue simply by making an unauthenticated HTTP request to the vulnerable proxy routes and supplying a target URL, and the lack of authentication and open nature of the proxy make this a high‑risk remote attack vector.
OpenCVE Enrichment