PT-2026-52113 · Appsmith+1 · Appsmith+1

CVE-2026-55454

·

Published

2026-06-24

·

Updated

2026-06-29

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Appsmith versions prior to 2.1
Description The bundled Caddy reverse-proxy admin API is bound to 0.0.0.0:2019 inside the container and lacks authentication by default. Although the listener is not published to the host, it remains accessible to the Appsmith server process or via a Server-Side Request Forgery (SSRF) — a technique where an attacker induces a server to make requests to an internal resource. An authenticated low-privileged user can exploit an SSRF to send requests to the 'POST /load' endpoint or other admin-API calls at http://0.0.0.0:2019/, allowing them to replace the active Caddy configuration and gain control of the reverse proxy.
Recommendations Update to version 2.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-APPSMITH-2026-55454
CVE-2026-55454
GHSA-8JVV-GWQG-6VJC

Affected Products

Appsmith
Caddy