Impact
This vulnerability allows an attacker who can edit a Wiki.js page to embed an image tag with the prefetch-candidate class. The Image Prefetch renderer will fetch the specified URL without validating protocol or host, which can be used to exfiltrate internal data or access cloud metadata endpoints. The impact is that the server acts as a proxy, potentially leaking sensitive information and enabling internal network reconnaissance.
Affected Systems
Wiki.js installations running version 2.5.314 or older are affected. The issue exists in the image-prefetch renderer module of the project hosted by requarks. All deployments that allow unauthenticated or partially authenticated users to edit pages are at risk, with the specific requirement of edit permissions.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, but the EPSS score of less than 1% signals that, at present, the exploitation likelihood is low. Nonetheless, because editing access is broader in many environments, the potential for internal reconnaissance remains significant. The vulnerability is not listed in CISA’s KEV catalog, but the attack vector is server‑side and requires only the ability to inject a crafted image element, which is typically granted to contributors or editors rather than anonymous users.
OpenCVE Enrichment