PT-2026-21559 · Traccar · Traccar

Djvirus9

·

Publicado

2026-02-23

·

Atualizado

2026-02-28

·

CVE-2026-25648

CVSS v3.1

8.7

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Traccar versions 6.11.1 and later
Description Traccar, an open-source GPS tracking system, is affected by a stored cross-site scripting (XSS) issue. Authenticated users can upload malicious SVG files as device images. The application does not sanitize these files and serves them with the image/svg+xml Content-Type, allowing embedded JavaScript to execute in the context of other users' browsers. The vulnerability allows for the execution of arbitrary JavaScript. The API Endpoint for file uploads is implicated in this issue. The vulnerable parameter is the SVG file itself, specifically the embedded JavaScript within the SVG file.
Recommendations Traccar versions 6.11.1 and later: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25648
GHSA-MC2G-MJQH-8X78

Produtos afetados

Traccar