PT-2026-95064 · Unknown · Ts3-Manager

·

CVE-2026-54253

·

Published

2026-09-17

·

Updated

2026-09-23

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions TS3 Manager versions prior to 2.2.6
Description The /api/download endpoint in packages/server/routes/api.js improperly handles the port query parameter, passing it to the socket.connect(port, host) function and returning the resulting error message as text/html without a Content Security Policy. This allows a reflected value to execute in the manager origin when a logged-in operator follows a crafted link. Additionally, the token cookie in packages/ui/src/store/modules/query.js lacks HttpOnly, Secure, and SameSite attributes, enabling a script to read the token and trigger the autofillform() event in packages/server/socket.js. This event returns a decoded JSON Web Token (JWT), which may contain the cleartext ServerQuery password, potentially leading to operator-session hijacking and full control of the managed TeamSpeak server if administrative credentials are used. A valid operator session and user interaction are required for exploitation.
Recommendations Update to version 2.2.6.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54253
GHSA-3CGM-7P4G-GFFJ

Affected Products

Ts3-Manager