CVE-2026-92795: Coze Studio through 0.5.1 Server-Side Request Forgery via Plugin
Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata endpoints and internal services reachable only from the backend network, reading responses containing sensitive information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Coze Studioto a version that resolves this vulnerability.Fixed in 0.5.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user who can register plugin tools can supply a server URL that causes the Coze Studio backend to make requests. The attacker does not need user interaction.
What systems or data may be exposed?
Services reachable only from the backend network, including cloud metadata endpoints, may be reachable through the vulnerable plugin request path. Responses containing sensitive information can be read by the attacker.
Are default deployments affected?
The available information does not state whether plugin-tool registration is enabled or available to users in a default deployment. Exposure depends on whether authenticated users can register plugin tools.