CVE-2026-18359
Last modified
CVE-2026-18359 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST /api/documents/{pk}/imports/, because the IMPORT_ALLOWED_DOMAINS setting defaults to '*' and no address filtering, redirect cap or timeout is applied. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST /api/documents/{pk}/imports/, because the IMPORT_ALLOWED_DOMAINS setting defaults to '*' and no address filtering, redirect cap or timeout is applied
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Escriptorium | Escriptorium | <= 26.04.1 |
References
- https://gitlab.com/scripta/escriptorium/-/work_items/1230Permissions Required
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-18359?
How severe is CVE-2026-18359?
How do I fix CVE-2026-18359?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18352The User Access Manager plugin for WordPress is vulnerable t…7.5
- CVE-2026-18353PIA's `POST /v1/upload/sbom` endpoint accepts a Bearer JWT a…8.8
- CVE-2026-18355A heap buffer overflow flaw was found in the SASL I/O layer …7.5
- CVE-2026-18356The Limit Login Attempts Reloaded WordPress plugin before 3.…3.7
- CVE-2026-18357The WPC Order Tip for WooCommerce WordPress plugin before 3.…7.5
- CVE-2026-18358A flaw was found in gnome-remote-desktop as shipped in Red H…7.5
- CVE-2026-1836The system stores the username and password from the login f…5.3
- CVE-2026-18360The IRIS web application in version 2.4.26 and possibly othe…7.6
- CVE-2026-18361The IRIS web application in version 2.4.26 and possibly othe…7.6
- CVE-2026-18362The IRIS web application in version 2.4.26 and possibly othe…5.9
- CVE-2026-18363A logic vulnerability in the password reset token validation…9.1
- CVE-2026-18364The zportals WordPress plugin before 6.4.2 does not perform …4.3
Are you affected by CVE-2026-18359?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
