Executive brief
Scripta eScriptorium is a document transcription and annotation platform. A vulnerability in its document import feature allows authenticated users to make the server perform HTTP requests to arbitrary internal hosts, including cloud metadata services that may contain sensitive credentials and configuration data, potentially compromising the entire infrastructure.
Technical details
This is a server-side request forgery (SSRF) vulnerability in the METS and IIIF import URI handling, accessible via the POST /api/documents/{pk}/imports/ endpoint. An authenticated attacker can control the mets_uri or iiif_uri parameters to force the server to issue HTTP requests to internal hosts. The vulnerability exists because the IMPORT_ALLOWED_DOMAINS setting defaults to '*' (allowing all domains), and no address filtering, redirect restrictions, or request timeouts are applied. An attacker can leverage this to enumerate internal network services, access cloud instance metadata endpoints, or exfiltrate sensitive data. Patches should implement strict domain whitelisting, block private IP ranges, and apply request timeouts.
Affected products
- Scripta eScriptorium through 26.04.1
Timeline
- 2026-08-06: disclosed