
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33486 is a Server-Side Request Forgery (SSRF) and Local File Inclusion (LFI) vulnerability in the roadiz/documents Composer package, specifically in the RZ\Roadiz\Documents\DownloadedFile::fromUrl() component of the Roadiz CMS. It allows an authenticated attacker with ROLE_ACCESS_DOCUMENTS permission to read arbitrary files from the server's local file system, including .env files, database credentials, and internal configuration files. The vulnerability affects roadiz/documents versions prior to 2.3.42, 2.5.44 (for the 2.4–2.5 branch), 2.6.28, and 2.7.9. It was published on March 22, 2026, and has a CVSS v3.1 base score of 6.8 (Moderate) per the GitHub Advisory, or 6.5 (Medium) per NVD scoring (GitHub Advisory, Roadiz Advisory).
The root cause is CWE-918 (Server-Side Request Forgery): the $url parameter in DownloadedFile::fromUrl() is passed directly to PHP's native fopen() function without any scheme validation or sanitization. Because PHP's stream wrappers support file:// URIs natively, an attacker can supply a file:///app/.env or similar URI, causing the application to read local files and store them as documents in the publicly accessible Media Library. The attack vector is network-based and exploited through the Podcast RSS Feed importer or OEmbed media import features — an attacker crafts a malicious XML feed containing an itunes:image href="file:///app/.env" attribute, which the AbstractPodcastFinder processes and passes to the vulnerable function. A detailed proof-of-concept with step-by-step reproduction instructions is publicly available in the security advisory (GitHub Advisory, Patch Commit).
Successful exploitation results in a total loss of confidentiality for the web application and potentially the underlying host. An attacker can exfiltrate sensitive files such as .env (containing API keys, APP_SECRET, and database credentials), security.yaml, SQLite database files, and /etc/passwd for system user enumeration. In cloud-hosted deployments (AWS, Azure, GCP), the SSRF vector can be extended to query internal metadata endpoints (e.g., http://169.254.169.254/latest/meta-data/), potentially enabling theft of IAM credentials and full cloud infrastructure compromise. There is no integrity or availability impact, but the confidentiality breach can enable complete horizontal and vertical privilege escalation (Roadiz Advisory).
A public proof-of-concept with concrete step-by-step exploitation instructions is available in the GitHub Security Advisory, classified as a high-confidence, real exploit by Feedly threat intelligence. Exploitation requires authentication with ROLE_ACCESS_DOCUMENTS privileges, which limits the attack surface but does not eliminate risk from insider threats or compromised accounts. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.026% (2nd percentile), indicating a low current probability of exploitation in the wild (GitHub Advisory, Roadiz Advisory).
roadiz/documents (< 2.3.42, < 2.5.44, < 2.6.28, or < 2.7.9). Obtain or compromise credentials for an account with ROLE_ACCESS_DOCUMENTS permission.podcast.xml) hosted on an attacker-controlled server. Inject a file:// URI into the itunes:image href attribute targeting a sensitive file:<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
<channel>
<title>Roadiz LFI Exploit</title>
<itunes:image href="file:///app/.env"/>
</channel>
</rss>podcast.xml file.AbstractPodcastFinder processes the XML and passes file:///app/.env to DownloadedFile::fromUrl(). PHP's fopen() reads the local file and stores its contents as a new Document in the Media Library (appearing as a broken image icon)..env, including database credentials, APP_SECRET, and API keys.file:///etc/passwd, file:///app/config/security.yaml, or cloud metadata endpoints (http://169.254.169.254/latest/meta-data/) to escalate further (Roadiz Advisory).169.254.169.254) originating from the PHP web process.fopen() calls with file:// URIs (on unpatched systems)..env contents, /etc/passwd format); temporary files in the PHP temp directory with names derived from sensitive file paths.Upgrade the roadiz/documents Composer package to one of the following patched versions: 2.3.42 (for the 2.3.x branch), 2.5.44 (for the 2.4–2.5 branches), 2.6.28 (for the 2.6.x branch), or 2.7.9 (for the 2.7.x branch). The fix adds a isSafeRemoteUrl() validation method that restricts fopen() calls to http:// and https:// schemes only, blocks private/reserved IP ranges, and rejects localhost hostnames. As interim mitigations: restrict ROLE_ACCESS_DOCUMENTS to only trusted users with a legitimate business need; implement network-level egress filtering to block outbound requests from the web server to internal IP ranges and cloud metadata endpoints; and monitor Media Library activity for unexpected document imports (GitHub Advisory, Patch Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."