Home

Description

ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file that references a remote URL. If the server processes the SVG file in a way that parses external references, it may initiate unintended outbound requests. This can be used to access internal services or resources.

PUBLISHED Reserved 2025-04-15 | Published 2025-10-17 | Updated 2025-10-17 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L

Problem types

CWE-918 Server-Side Request Forgery (SSRF)

Product status

Default status
unaffected

Any version before 4.2.1
affected

Credits

Tamil Mathi finder

References

github.com/thingsboard/thingsboard/releases/tag/v4.2.1 release-notes patch

github.com/thingsboard/thingsboard/pull/13927 patch

www.vulncheck.com/advisories/thingsboard-svg-image-ssrf third-party-advisory

cve.org (CVE-2025-34282)

nvd.nist.gov (CVE-2025-34282)

Download JSON