Server-Side Request Forgery (SSRF) in WPGraphQL - #VU148860
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote user to access internal services and disclose sensitive information.
The vulnerability exists due to an incomplete list of disallowed inputs in the createMediaItem GraphQL mutation when processing filePath URLs that use DNS hostnames resolving to link-local addresses. A remote user can submit a crafted filePath URL using a DNS hostname that resolves to a link-local address to access internal services and disclose sensitive information.
On cloud hosts exposing IMDSv1, temporary cloud credentials may be exposed through the Media Library.