External risk intelligence

Webstudio SSRF via CGI Proxy Routes

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-86119

The vulnerability resides in proxy routes (/cgi/image, /cgi/video, /cgi/asset) within a web application platform. These types of endpoints are typically exposed as part of the public-facing web interface to handle media processing and asset delivery, making them commonly reachable by internet traffic in standard deployments of the application.

Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Webstudio that could allow unauthorized access to sensitive cloud instance metadata and internal services. The issue arises from an unauthenticated server-side request forgery flaw within specific proxy routes when a particular environment variable is not set. This could enable attackers to perform reconnaissance on your infrastructure and potentially access internal systems.

  • Unauthenticated flaw in proxy routes.
  • Could expose internal cloud infrastructure.
  • Confirm relevance and exposure of this technology.

Attack Path

How an attacker could exploit the issue

An attacker can initiate a journey by reaching the application's proxy routes, specifically those handling images, videos, or assets. These routes, when misconfigured with a missing environment variable, become vulnerable. By supplying a specially crafted URL to these endpoints, an attacker can trick the server into making requests on their behalf. This can expose sensitive cloud instance metadata, allow access to internal services, and facilitate reconnaissance of the underlying infrastructure.

  • No authentication required.
  • Triggers by sending a crafted URL.
  • Risk: metadata access, internal service access.

Live Threat

Current exploitation, exposure, and threat context

When the `RESIZE_ORIGIN` environment variable is unset, unauthenticated attackers can exploit a server-side request forgery in the `/cgi/image`, `/cgi/video`, and `/cgi/asset` proxy routes. This allows them to send arbitrary URLs, potentially exposing cloud instance metadata, internal services, and enabling network reconnaissance of the instance's infrastructure.

  • Instance metadata and internal services at risk.
  • Arbitrary URLs read by proxy endpoints.
  • Network reconnaissance and service access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This Server-Side Request Forgery (SSRF) vulnerability impacts systems running Webstudio, potentially exposing cloud instance metadata and internal services. Infrastructure and platform teams, alongside security operations, should prioritize identifying all instances of Webstudio, assessing their exposure to external networks, and confirming business criticality. Once identified and prioritized, coordinate remediation efforts with application owners and the vendor.

  • Platform and Infrastructure teams own remediation.
  • Verify external reachability and asset criticality.
  • Plan coordinated vendor and internal updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Webstudio?

Webstudio is a visual development platform used to build and deploy websites and web applications. It includes integrated tools for asset management, such as processing images, videos, and other media. This software is often deployed in cloud environments where it interacts with instance-specific services to manage or deliver content.

What is the Server-Side Request Forgery vulnerability in CVE-2026-86119?

This flaw, classified as CWE-918, occurs when a server is tricked into making requests to locations an attacker chooses. In this case, the vulnerability allows an unauthenticated user to send arbitrary URLs through Webstudio's media proxy routes. Instead of fetching the intended asset, the server follows the attacker's instructions, potentially returning data from internal network locations that should remain private.

How can an attacker trigger this vulnerability?

An attacker triggers the bug by sending a crafted request to the /cgi/image, /cgi/video, or /cgi/asset endpoints without needing any login credentials. The vulnerability only manifests when the RESIZE_ORIGIN environment variable is unset. If this variable is correctly configured in your environment, the proxy routes do not perform the unauthorized requests, effectively blocking this specific attack path.

Is my Webstudio installation at risk?

Halo Surface Signal indicates that the affected proxy routes are typically designed for public-facing media delivery. Because these endpoints are commonly exposed to the internet to function, your instance is likely reachable by unauthorized traffic. If your Webstudio deployment is accessible externally, you should assume the risk of potential reconnaissance or metadata exposure is high.

How do I respond to CVE-2026-86119?

Begin by identifying every instance of Webstudio running in your environment and verify their network exposure. Prioritize confirming the status of the RESIZE_ORIGIN environment variable, as ensuring it is set is a critical step in mitigating the risk. Coordinate with your application owners to track official vendor updates and apply them as soon as they become available to permanently resolve the underlying proxy vulnerability.

References