Description
Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img elements with the prefetch-candidate class to make the server request internal services and cloud metadata endpoints, with responses returned to the attacker.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Server-Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows an attacker who can edit a Wiki.js page to embed an image tag with the prefetch-candidate class. The Image Prefetch renderer will fetch the specified URL without validating protocol or host, which can be used to exfiltrate internal data or access cloud metadata endpoints. The impact is that the server acts as a proxy, potentially leaking sensitive information and enabling internal network reconnaissance.

Affected Systems

Wiki.js installations running version 2.5.314 or older are affected. The issue exists in the image-prefetch renderer module of the project hosted by requarks. All deployments that allow unauthenticated or partially authenticated users to edit pages are at risk, with the specific requirement of edit permissions.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, but the EPSS score of less than 1% signals that, at present, the exploitation likelihood is low. Nonetheless, because editing access is broader in many environments, the potential for internal reconnaissance remains significant. The vulnerability is not listed in CISA’s KEV catalog, but the attack vector is server‑side and requires only the ability to inject a crafted image element, which is typically granted to contributors or editors rather than anonymous users.

Generated by OpenCVE AI on September 18, 2026 at 06:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Wiki.js update (2.5.315 or later) where the image-prefetch renderer has been fixed.
  • Restrict page editing permissions to trusted users or audit current access controls to ensure only authorized personnel can add or modify page content.
  • If an immediate update is not possible, remove the prefetch-candidate class from the page templates or disable the image-prefetch renderer entirely to prevent the server from fetching external resources.

Generated by OpenCVE AI on September 18, 2026 at 06:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img elements with the prefetch-candidate class to make the server request internal services and cloud metadata endpoints, with responses returned to the attacker.
Title Wiki.js through 2.5.314 Server-Side Request Forgery via Image Prefetch
First Time appeared Requarks
Requarks wiki.js
Weaknesses CWE-918
CPEs cpe:2.3:a:requarks:wiki.js:*:*:*:*:*:*:*:*
Vendors & Products Requarks
Requarks wiki.js
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Requarks Wiki.js
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T15:48:56.182Z

Reserved: 2026-09-16T19:15:40.054Z

Link: CVE-2026-92775

cve-icon Vulnrichment

Updated: 2026-09-21T15:48:50.894Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:26.390

Modified: 2026-09-24T21:08:22.573

Link: CVE-2026-92775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)