CVE-2026-92775: Wiki.js through 2.5.314 Server-Side Request Forgery via Image Prefetch

Published Sep 16, 2026
·
Updated

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img elements with the prefetch-candidate class to make the server request internal services and cloud metadata endpoints, with responses returned to the attacker.

Affected Software

1 affected component
Wiki.js Wiki.js<=2.5.314

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs page editing permissions and must be able to add an img element with the prefetch-candidate class. The vulnerable renderer then fetches the supplied URL from the Wiki.js server.

2

What systems or data could be exposed?

The server can be induced to request arbitrary URLs, including internal services and cloud metadata endpoints. Responses from those requests are returned to the attacker, so exposure depends on what the Wiki.js server can reach.

3

Are default deployments affected?

The provided information identifies affected Wiki.js versions through 2.5.314, but it does not state whether Image Prefetch is enabled or reachable in a default configuration.

4

What can be done if patching is not immediately possible?

Limit page editing permissions to trusted users, since exploitation requires editing access. Restrict the Wiki.js server's network access to internal services and cloud metadata endpoints where possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203