Description
TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and returns the resulting error.message through res.status(400).send(error.message) as text/html without a Content Security Policy. When a logged-in operator follows a crafted top-level link, the reflected value executes in the manager origin. The token cookie set in packages/ui/src/store/modules/query.js lacks HttpOnly, Secure, and an explicit SameSite attribute, allowing the script to read the token and call the autofillform event in packages/server/socket.js. autofillform returns the decoded JWT, including the cleartext ServerQuery password, enabling operator-session hijacking and control of the managed TeamSpeak server when the operator uses administrative ServerQuery credentials. A valid operator session and user interaction are required. This issue is fixed in 2.2.6.
Published: 2026-09-17
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Reflected XSS with operator-session hijacking
Action: Apply Patch
AI Analysis

Impact

TS3 Manager’s /api/download handler returns the value of an attacker-controlled port query parameter in an error message that is sent as plain text/html without a Content Security Policy. Because the token cookie is not marked HttpOnly, Secure, or SameSite, a reflected script can read that cookie, decode the JWT, and obtain the TeamSpeak server’s cleartext ServerQuery password. With an active operator session and user interaction, the attacker can then hijack the operator’s session and execute administrative commands on the managed server. The vulnerability therefore provides the attacker with privileged access to the TeamSpeak server after authentication and a crafted link is visited.

Affected Systems

All installations of TS3 Manager released before version 2.2.6 are affected. The latest official release, v2.2.6, contains a fix that removes the insecure handling of the port parameter and prevents the reflected XSS. No other vendor or product variants are listed as affected.

Risk and Exploitability

The vulnerability is scored as CVSS 8.2, indicating a high severity misconfiguration that leads to serious privilege escalation. The EPSS score of below 1% suggests that exploitation is currently rare, and the issue is not yet catalogued in CISA’s KEV list. Exploitation requires a legitimate operator account, user interaction with a crafted link, and a web browser that accepts the reflected payload. When these conditions are met, an attacker can gain full administrative control over the TeamSpeak server. The lack of a Content Security Policy and insecure cookie practices are the core technical weaknesses that enable this attack.

Generated by OpenCVE AI on September 19, 2026 at 00:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update TS3 Manager to version 2.2.6 or later to apply the vendor patch that eliminates the reflected XSS
  • Enforce stronger cookie attributes for the token cookie—mark it HttpOnly, Secure, and set SameSite to Lax or Strict—to prevent client‑side scripts from reading it
  • Implement a robust Content Security Policy on the manager web interface to restrict execution of reflected or inline scripts

Generated by OpenCVE AI on September 19, 2026 at 00:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Joni1802
Joni1802 ts3 Manager
Vendors & Products Joni1802
Joni1802 ts3 Manager

Thu, 17 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and returns the resulting error.message through res.status(400).send(error.message) as text/html without a Content Security Policy. When a logged-in operator follows a crafted top-level link, the reflected value executes in the manager origin. The token cookie set in packages/ui/src/store/modules/query.js lacks HttpOnly, Secure, and an explicit SameSite attribute, allowing the script to read the token and call the autofillform event in packages/server/socket.js. autofillform returns the decoded JWT, including the cleartext ServerQuery password, enabling operator-session hijacking and control of the managed TeamSpeak server when the operator uses administrative ServerQuery credentials. A valid operator session and user interaction are required. This issue is fixed in 2.2.6.
Title TS3 Manager: Reflected XSS via /api/download port parameter steals operator session
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Joni1802 Ts3 Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-23T19:44:00.241Z

Reserved: 2026-06-12T16:25:43.086Z

Link: CVE-2026-54253

cve-icon Vulnrichment

Updated: 2026-09-23T19:43:38.028Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T19:16:50.203

Modified: 2026-09-30T17:32:07.107

Link: CVE-2026-54253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:45:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')