Description
CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled URL through importBasemapURL() in api/routes/basemap.ts to fetch(url) without resolved-address classification or redirect revalidation. BasemapProtocol.isValidURL in api/lib/interface-basemap.ts checks only the HTTP or HTTPS scheme and is not applied on the vulnerable import path. Direct internal addresses, alternate IP encodings, and redirects to internal addresses can reach cloud metadata, loopback, private, and CGNAT HTTP services. The OptionalTileJSON response reflects fields including name, attribution, and tiles[0] to the caller, making the request forgery full-read rather than blind and enabling cloud credential theft and internal service disclosure. This issue is fixed in version 13.22.1.
Published: 2026-09-17
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Internal Information Disclosure and Credential Theft
Action: Patch
AI Analysis

Impact

The vulnerability allows an authenticated user to perform a server-side request forgery against the CloudTAK basemap import endpoint (PUT /api/basemap). The implementation accepts an attacker-specified URL and forwards it to the server's fetch call without applying address‑classification or redirect validation. As a result, the server can resolve internal or cloud‑metadata addresses, causing the attacker to receive the full HTTP response—including headers such as name, attribution, and tiles[0]—directly in the API response. This provides read access to internal services and cloud metadata, enabling credential theft or internal service disclosure.

Affected Systems

This flaw exists in CloudTAK deployments from dfpc‑coe prior to version 13.22.1. Users running any version older than the released 13.22.1 build are affected.

Risk and Exploitability

The CVSS score is 5, indicating moderate severity, while the EPSS score is less than 1%, suggesting low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to authenticate to the application, submit a malicious URL, and is limited to internal or cloud resources reachable from the application’s network. Once the request is made, the attacker obtains the entire response payload, potentially exposing secrets and internal addresses.

Generated by OpenCVE AI on September 19, 2026 at 02:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CloudTAK to version 13.22.1 or later to apply the fixed URL validation and redirect checks.
  • Restrict access to the /api/basemap import endpoint so that only trusted and minimal‑privilege users can invoke it.
  • Enforce network controls so that the CloudTAK application cannot initiate outbound connections to internal or cloud‑metadata IP ranges.

Generated by OpenCVE AI on September 19, 2026 at 02:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vqrw-qphh-p34v TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dfpc-coe
Dfpc-coe cloudtak
Vendors & Products Dfpc-coe
Dfpc-coe cloudtak

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled URL through importBasemapURL() in api/routes/basemap.ts to fetch(url) without resolved-address classification or redirect revalidation. BasemapProtocol.isValidURL in api/lib/interface-basemap.ts checks only the HTTP or HTTPS scheme and is not applied on the vulnerable import path. Direct internal addresses, alternate IP encodings, and redirects to internal addresses can reach cloud metadata, loopback, private, and CGNAT HTTP services. The OptionalTileJSON response reflects fields including name, attribution, and tiles[0] to the caller, making the request forgery full-read rather than blind and enabling cloud credential theft and internal service disclosure. This issue is fixed in version 13.22.1.
Title CloudTAK: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Dfpc-coe Cloudtak
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T17:42:43.845Z

Reserved: 2026-06-15T19:04:14.455Z

Link: CVE-2026-54546

cve-icon Vulnrichment

Updated: 2026-09-17T17:42:40.417Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T18:16:46.207

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-54546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)