CVE-2026-92795 Details
Description
Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata endpoints and internal services reachable only from the backend network, reading responses containing sensitive information.
A server-side request forgery (SSRF) vulnerability has been identified in Coze Studio versions through 0.5.1. This vulnerability allows authenticated users to manipulate the server URL used in plugin tool registrations, enabling them to access internal services and cloud metadata endpoints that are normally restricted. The exploitation of this vulnerability could lead to unauthorized access to sensitive information by allowing interception of responses from these internal services.
Coze Studio has released a patch for this vulnerability. Users should update to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/coze-dev/coze-studio/issues/2711 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/coze-dev/coze-studio | [email protected] | ProductSource CodeVendor |
| https://github.com/coze-dev/coze-studio/blob/22275b1c2661d35344a7493cffe401e8cc61cf8e/backend/domain/plugin/service/tool/invocation_http.go#L127-L146 | [email protected] | Source CodeVendor |
| https://github.com/coze-dev/coze-studio/issues/2711 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/coze-studio-through-0.5.1-server-side-request-forgery-via-plugin | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Coze Studio | <= 0.5.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion