CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification
- Severity:
- High
Description
No description available.
Recommendation
Update the @tak-ps/cloudtak package to the latest compatible version. Followings are version details:
- Affected version(s): < 13.10.0
- Patched version(s): 13.10.0
References
Related Issues
- TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification g - CVE-2026-54546
- SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user - CVE-2026-34524
- PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments - CVE-2026-45623
- SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6 - CVE-2026-34526
You might also like:
- Tags:
- npm
- @tak-ps/cloudtak
Anything's wrong? Let us know Last updated on July 17, 2026


