No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 11 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Appwrite up to 2.3.0. This vulnerability affects the function PublicHostname of the file src/Appwrite/Platform/Modules/Avatars/Http/Screenshots/Get.php of the component Browser Screenshot Service. This manipulation of the argument url causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is able to resolve this issue. Patch name: 393255e7302ae5503331d45802e2eee01c6a47fe. You should upgrade the affected component. | |
| Title | Appwrite Browser Screenshot Service Get.php PublicHostname server-side request forgery | |
| First Time appeared |
Appwrite
Appwrite appwrite |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Appwrite
Appwrite appwrite |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-11T22:15:24.426Z
Reserved: 2026-10-11T07:23:33.337Z
Link: CVE-2026-108770
No data.
No data.
No data.
OpenCVE Enrichment
No data.