PT-2026-52103 · Appsmith+2 · Appsmith+2

CVE-2026-50189

·

Published

2026-06-24

·

Updated

2026-06-29

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Appsmith versions prior to 2.1
Description The bundled supervisord exposes an XML-RPC interface on port 9001, which is accessible from outside the container through a Caddy reverse-proxy route at the '/supervisor/*' endpoint. An authenticated administrator can retrieve the APPSMITH SUPERVISOR PASSWORD variable via the 'GET /api/v1/admin/env' endpoint. By combining these, an attacker can send arbitrary XML-RPC calls to supervisord and execute operating system commands within the Docker container using the twiddler.addProgramToGroup() function.
Recommendations Update to version 2.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-APPSMITH-2026-50189
CVE-2026-50189
GHSA-V49V-673J-G4VJ

Affected Products

Appsmith
Caddy
Supervisor