Junglewise Threat Intelligence

CVE-2026-75332: Zyplayer-Doc server-side request forgery in page download

CVE-2026-75332 · Severity: critical · CVSS 9.1 · Published 2026-08-26

Executive brief

Zyplayer-Doc, a wiki-based document management system, contains a Server-Side Request Forgery vulnerability in its page download functionality that allows attackers to make arbitrary HTTP requests from the server. An attacker with authenticated access can inject malicious image URLs into wiki content, causing the server to attempt connections to internal network services and ports, potentially exposing internal infrastructure and services. This can lead to data exfiltration, reconnaissance of internal networks, or attacks against internal systems.

Technical details

The vulnerability exists in WikiPageWebService.download(), which parses wiki content using Jsoup to extract <img src> URLs and downloads them using HttpUtil.createGet(src).execute() without any URL validation or filtering. The vulnerable endpoint /zyplayer-doc-wiki/page/download accepts user-controlled HTML content containing image source attributes that are processed server-side. Attackers must be authenticated but can leverage zero-validation URL parsing to craft SSRF payloads targeting localhost, internal networks (RFC1918 ranges), or other network-accessible services. The attack enables port scanning, internal service discovery, and potential exploitation of internal-only services. Patches addressing URL validation in download operations have been made available in versions after 1.0.0.

Affected products

  • Zyplayer Zyplayer-Doc <=1.0.0

Timeline

  • 2026-08-26: disclosed

References