CVE-2026-92931 PUBLISHED

CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK

Assigner: ProgressSoftware
Reserved: 17.09.2026 Published: 05.10.2026 Updated: 05.10.2026

CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor Progress Software
Product @progress/sitefinity-nextjs-sdk
Versions Default: unaffected
  • affected from 15.1.8326 to 15.4.8638 (excl.)

Credits

  • Abhishek Nandkumar Bhaskar (Abhi-Hackz) finder

References

Problem Types

  • CWE-918: Server-Side Request Forgery CWE

Impacts

  • CAPEC-664: Server Side Request Forgery