PT-2026-21559 · Traccar · Traccar
Djvirus9
·
Published
2026-02-23
·
Updated
2026-02-28
·
CVE-2026-25648
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Traccar versions 6.11.1 and later
Description
Traccar, an open-source GPS tracking system, is affected by a stored cross-site scripting (XSS) issue. Authenticated users can upload malicious SVG files as device images. The application does not sanitize these files and serves them with the
image/svg+xml Content-Type, allowing embedded JavaScript to execute in the context of other users' browsers. The vulnerability allows for the execution of arbitrary JavaScript. The API Endpoint for file uploads is implicated in this issue. The vulnerable parameter is the SVG file itself, specifically the embedded JavaScript within the SVG file.Recommendations
Traccar versions 6.11.1 and later: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Traccar