CVE-2026-108770 | Appwrite up to 2.3.0 Browser Screenshot Service Get.php PublicHostname url server-side request forgery
A vulnerability identified as problematic has been detected in Appwrite up to 2.3.0. This vulnerability affects the function PublicHostname of the file src/Appwrite/Platform/Modules/Avatars/Http/Screenshots/Get.php of the component Browser Screenshot Service. This manipulation of the argument url causes server-side request forgery.
This vulnerability is handled as CVE-2026-108770. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More