PT-2026-52113 · Appsmith+1 · Appsmith+1
CVE-2026-55454
·
Published
2026-06-24
·
Updated
2026-06-29
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Appsmith versions prior to 2.1
Description
The bundled Caddy reverse-proxy admin API is bound to 0.0.0.0:2019 inside the container and lacks authentication by default. Although the listener is not published to the host, it remains accessible to the Appsmith server process or via a Server-Side Request Forgery (SSRF) — a technique where an attacker induces a server to make requests to an internal resource. An authenticated low-privileged user can exploit an SSRF to send requests to the 'POST /load' endpoint or other admin-API calls at http://0.0.0.0:2019/, allowing them to replace the active Caddy configuration and gain control of the reverse proxy.
Recommendations
Update to version 2.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Appsmith
Caddy