CVE-2026-108770 | Appwrite up to 2.3.0 Browser Screenshot Service Get.php PublicHostname url server-side request forgery

SecurityVulns

A vulnerability identified as problematic has been detected in Appwrite up to 2.3.0. This vulnerability affects the function PublicHostname of the file src/Appwrite/Platform/Modules/Avatars/Http/Screenshots/Get.php of the component Browser Screenshot Service. This manipulation of the argument url causes server-side request forgery.

This vulnerability is handled as CVE-2026-108770. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More