Sceawere

Vulnerability Detail

CVE-2026-92931UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SSRF in Progress Sitefinity-NextJS-SDK

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
5h ago
Vendor
Progress Software
Product
@progress/sitefinity-nextjs-sdk
Attack Type
CWE-918: Server-Side Request Forgery
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-05T14:17:21.323Z",
  "pubdate": "2026-10-05T14:17:21.323Z",
  "executiveSummary": "The Progress @progress/sitefinity-nextjs-sdk is susceptible to a Server-Side Request Forgery (SSRF) vulnerability, classified under CWE-918. This flaw allows a remote, unauthenticated attacker to manipulate the SDK into initiating unauthorized HTTP requests to arbitrary, attacker-controlled destinations. By inducing the application server to perform these outbound requests, the attacker can bypass network access controls, perform internal network reconnaissance, or interact with services restricted to the server's local environment. The vulnerability affects versions 15.1.8326 through 15.4.8637. Successful exploitation poses a significant security risk, as it may lead to the unauthorized disclosure of sensitive configuration data, internal API responses, or metadata, potentially facilitating lateral movement or further exploitation within the hosting infrastructure. Because the requests originate from the trusted application server, they often evade perimeter security measures such as firewalls that rely on origin-based filtering.",
  "technicalDetails": "The root cause of the vulnerability lies in the improper validation or sanitization of user-supplied input that governs the destination URL for outbound requests initiated by the @progress/sitefinity-nextjs-sdk. The library functions responsible for fetching resources from the Sitefinity backend fail to strictly enforce an allowlist of permitted hosts or protocols, enabling an attacker to inject arbitrary URIs.\nThe attack flow begins when an attacker identifies an endpoint or parameter within the Next.js application that utilizes the vulnerable SDK to perform back-end data retrieval. By supplying a malicious URI—typically pointing to an internal resource (e.g., localhost or internal management interfaces) or an external attacker-controlled server—the attacker forces the application process to act as a proxy. When the SDK processes this input, it initiates a request using the manipulated URL string, effectively masquerading the attacker's request as legitimate traffic originating from the application server.\nSpecifically, when the affected SDK versions 15.1.8326 through 15.4.8637 process these requests, they do not sufficiently neutralize protocol-based attacks or verify the target infrastructure. In a cloud-native or containerized environment, this can be leveraged to probe metadata services (e.g., 169.254.169.254) to exfiltrate identity tokens or configuration secrets. The vulnerability does not require authentication or elevated privileges, as the entry point is exposed to remote users interacting with the application.\nThe post-exploitation impact is multifaceted. Beyond the direct exfiltration of sensitive information, the ability to perform SSRF allows for internal network mapping by observing latency or error responses from internal services that are otherwise inaccessible from the public internet. Furthermore, the attacker can interact with non-public REST APIs, administrative consoles, or internal microservices, potentially leading to remote code execution or data destruction if those internal services lack robust authentication. The vulnerability persists until the input handling logic in the SDK is updated to implement strict URL parsing and whitelist-based domain validation."
}
CVE-2026-92931: SSRF in Progress Sitefinity-NextJS-SDK (HIGH Severity, CVSS: 8.8) | Sceawere