Vulnerability library
Security checkJuly 17, 2026

TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification g

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpm@tak-ps/cloudtak

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

PUT /api/basemap (the basemap import endpoint) fetches an attacker-supplied URL server-side with no SSRF protection whatsoever. Any authenticated user can submit a JSON body { "type": "...", "url": "<attacker url>" }; the server calls fetch(url) against that URL and then reflects the response body (name, attribution, tiles[0], zoom levels) back to the caller in the OptionalTileJSON response.

Recommendation

No fix is available yet. Followings are affected versions:

  • <= 13.5.0

References

Could your website be exposed too?

SmartScanner can check your website for TAK-PS-Stats Web UI: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification g and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 17, 2026