PT-2025-30343 · Manager Io · Imanager

·

CVE-2025-54122

·

Published

2025-07-21

·

Updated

2026-07-21

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Manager-io/Manager versions prior to 25.7.21.2525
Description An unauthenticated full read Server-Side Request Forgery (SSRF) issue exists in the proxy handler component. This allows an attacker to bypass network isolation and access restrictions, potentially enabling access to internal services, cloud metadata endpoints, and the exfiltration of sensitive data from isolated network segments via the 'proxy' endpoint.
Recommendations Update to version 25.7.21.2525.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54122
GHSA-347W-CGWH-M895

Affected Products

Imanager