CVE-2026-55177 CloudTAK ESRI 路由服务端请求伪造漏洞
影响任意已认证用户可读取云实例元数据及内网服务响应
CloudTAK 是兼容 TAK 的浏览器端通用作战图与态势感知工具。其 ESRI 辅助路由族(api/routes/esri.ts)将请求中完全由攻击者控制的 URL 直接交给 api/lib/esri.ts 中的 EsriBase/EsriProxyPortal/EsriProxyServer/EsriProxyLayer,并使用 @tak-ps/etl 的裸 fetch 发起请求。由于全程未做 IP/DNS/主机名分类校验,目标地址不会与私有、回环或链路本地网段比对,导致服务端请求伪造(SSRF)。
影响范围
CloudTAK 13.10.0 之前的版本受影响;具体受影响版本范围以官方公告为准。
漏洞详情
漏洞类型为服务端请求伪造(SSRF),成因是 ESRI 相关路由未对用户提供的 URL 做任何目标地址校验,直接由服务端发起出站请求。利用方式为:任意持有有效令牌的已认证用户(路由仅要求 Auth.is_auth 且 anyResources 为 true,无需管理员权限)通过 POST /api/esri 的 body url 参数,或 GET /api/esri/* 的 portal/server/layer 查询参数,指定内网地址。该 SSRF 为全读型而非盲打:请求成功时上游返回的 JSON 响应体会通过 res.json(...) 回传给调用者,失败时也会返回上游错误信息。
利用条件与风险
利用前提是攻击者拥有任意有效认证令牌,无需管理员权限。实战中可访问云实例元数据服务(169.254.169.254)、回环管理端口(127.0.0.1:<port>)及仅部署 VPC 内可达的主机,可能造成凭据泄露与内网信息探测。
修复建议
官方已在 13.10.0 版本修复,建议升级至 13.10.0 或更高版本。临时缓解措施包括限制 CloudTAK 服务端的出站网络访问、对私有/回环/链路本地地址做阻断,并收紧认证令牌的发放范围;具体修复细节以官方公告为准。
CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.10.0, every route in the ESRI helper family (api/routes/esri.ts) takes a fully attacker-controlled URL from the request (POST /api/esri body url, and the portal / server / layer query parameters on the GET /api/esri/* routes) and passes it into EsriBase / EsriProxyPortal / EsriProxyServer / EsriProxyLayer in api/lib/esri.ts, which fetch it with the bare fetch from @tak-ps/etl. No IP / DNS / hostname classification is applied at any point, so the destination is never validated against private, loopback, or link-local ranges. Any authenticated user (the routes only require Auth.is_auth(config, req, { anyResources: true }), i.e. any token, not an admin) can therefore make the CloudTAK server issue arbitrary outbound GET/POST requests to internal addresses such as the cloud instance-metadata service (169.254.169.254), loopback admin ports (127.0.0.1:), and other hosts reachable only from inside the deployment VPC. This is a full-read SSRF, not blind: on success the upstream JSON body is returned to the caller via res.json(…), and on failure the upstream error string is reflected verbatim as ESRI Server Error: . An attacker can read cloud metadata (and the temporary IAM credentials the instance role exposes), enumerate internal services, and exfiltrate their response bodies. The sniff() URL classifier provides no protection: it only pattern-matches the pathname (/rest, /arcgis/rest, /sharing/rest), so a URL like http://169.254.169.254/arcgis/rest or http://127.0.0.1:8500/rest passes sniff() and is fetched. This issue has been patched in version 13.10.0.