PT-2026-29787 · Unknown · Huimeicloud Hm Editor
Bigw
·
Published
2026-04-02
·
Updated
2026-04-02
·
CVE-2026-5346
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
huimeicloud hm editor versions up to 2.2.3
Description
A flaw exists in the
client.get function within the image-to-base64 component, specifically in the file src/mcp-server.js. Manipulation of the url argument can result in server-side request forgery (SSRF). This issue is remotely exploitable. The details of the flaw have been publicly disclosed, and the vendor was notified but did not respond.Recommendations
Update huimeicloud hm editor to a version later than 2.2.3.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huimeicloud Hm Editor