PT-2026-29787 · Unknown · Huimeicloud Hm Editor

Bigw

·

Published

2026-04-02

·

Updated

2026-04-02

·

CVE-2026-5346

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions huimeicloud hm editor versions up to 2.2.3
Description A flaw exists in the client.get function within the image-to-base64 component, specifically in the file src/mcp-server.js. Manipulation of the url argument can result in server-side request forgery (SSRF). This issue is remotely exploitable. The details of the flaw have been publicly disclosed, and the vendor was notified but did not respond.
Recommendations Update huimeicloud hm editor to a version later than 2.2.3.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-5346

Affected Products

Huimeicloud Hm Editor