
ZAST identified and verified CVE-2026-2711 in worldquant-miner (<=1.0.9). A user-controlled URL reached the server-side fetch flow at /console/api/remote-files. That is enough to turn a convenience feature into SSRF. https://t.co/HuOuDwmLpA
Post summary
ZAST announced the discovery of CVE-2026-2711 in worldquant‑miner, identifying a SSRF flaw caused by a user‑controlled URL in the /console/api/remote-files endpoint; a supporting PoC link is included.


