Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54546— CloudTAK: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard

Quick assessment

Affected
dfpc-coe CloudTAK
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: CloudTAK 简介与漏洞描述 CloudTAK 是一款基于浏览器的通用态势感知与态势意识(Common Operating Picture)工具,与 TAK 兼容。 在版本 13.22.1 之前,已认证的 端点会将攻击者可控的 URL 通过 中的 函数传递给 ,且在获取数据前,既未对解析后的地址进行分类检查,也未对重定向进行再验证。 中的 仅检查 URL 的协议是否为 HTTP 或 HTTPS,但该检查并未在存在漏洞的导入路径中生效。因此,直接指向内部地址、各种 IP 地址的替代编

CVSS 5.0 · Medium

Possible ATT&CK Techniques 1 AI

T1041 · Exfiltration Over C2 Channel

Affected Version Matrix 1

VendorProduct Version RangeStatus
dfpc-coe CloudTAK < 13.22.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54546

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CloudTAK: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard
Source: CVE Program / CVE List V5
Vulnerability Description
CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled URL through importBasemapURL() in api/routes/basemap.ts to fetch(url) without resolved-address classification or redirect revalidation. BasemapProtocol.isValidURL in api/lib/interface-basemap.ts checks only the HTTP or HTTPS scheme and is not applied on the vulnerable import path. Direct internal addresses, alternate IP encodings, and redirects to internal addresses can reach cloud metadata, loopback, private, and CGNAT HTTP services. The OptionalTileJSON response reflects fields including name, attribution, and tiles[0] to the caller, making the request forgery full-read rather than blind and enabling cloud credential theft and internal service disclosure. This issue is fixed in version 13.22.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
dfpc-coe CloudTAK < 13.22.1 -

II. Public POCs for CVE-2026-54546

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54546

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54546 (3)

Vendor Advisories for CVE-2026-54546 (1)

Vendor Pages for CVE-2026-54546 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54546

No comments yet


Leave a comment