Description
Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata endpoints and internal services reachable only from the backend network, reading responses containing sensitive information.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

Coze Studio permits authenticated users to supply arbitrary URLs when registering plugin tools, and the backend fetches those URLs without validation. This flaw allows an attacker to trigger the server to request internal or cloud metadata endpoints and read the returned data. The potential impact is the disclosure of sensitive information such as internal service responses, configuration data, or credentials that are normally protected behind the internal network.

Affected Systems

The vulnerability exists in Coze Studio version 0.5.1 and earlier, developed by coze‑dev. The affected component is the plugin registration service that accepts external URLs.

Risk and Exploitability

The CVSS score of 7.1 classifies this as a high severity flaw. With an EPSS score below 1 %, the likelihood of immediate exploitation is low, and the vulnerability is not yet listed in the CISA Known Exploited Vulnerabilities catalog. Attackers must be authenticated to register a plugin, but once authenticated they can coerce the backend into accessing any internal endpoint reachable from the backend network. The primary risk is information disclosure; remote code execution is not supported by the available information.

Generated by OpenCVE AI on September 17, 2026 at 21:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Coze Studio to a version newer than 0.5.1 as soon as a patch is available
  • If an upgrade cannot be performed, disable or restrict the plugin registration feature so that only whitelisted domains can be used
  • Apply network segmentation or firewalls to block the Coze Studio backend from reaching internal services and cloud metadata endpoints

Generated by OpenCVE AI on September 17, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata endpoints and internal services reachable only from the backend network, reading responses containing sensitive information.
Title Coze Studio through 0.5.1 Server-Side Request Forgery via Plugin
First Time appeared Coze
Coze coze Studio
Weaknesses CWE-918
CPEs cpe:2.3:a:coze:coze_studio:*:*:*:*:*:*:*:*
Vendors & Products Coze
Coze coze Studio
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Coze Coze Studio
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:04:55.507Z

Reserved: 2026-09-16T19:40:20.905Z

Link: CVE-2026-92795

cve-icon Vulnrichment

Updated: 2026-09-17T15:04:50.515Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:29.227

Modified: 2026-09-24T20:48:01.433

Link: CVE-2026-92795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)