Vulnerabilities/

CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification

Severity:
High

Description

No description available.

Recommendation

Update the @tak-ps/cloudtak package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@tak-ps/cloudtak
Anything's wrong? Let us know Last updated on July 17, 2026