3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be leveraged to obtain code execution and persistent access as the user running Xray (including root when Xray is running as root). This vulnerability is fixed in 3.3.1.
References
Configurations
No configuration.
History
25 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/MHSanaei/3x-ui/security/advisories/GHSA-jm48-m3rr-9hgg - |
25 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-25 16:16
Updated : 2026-06-25 20:21
NVD link : CVE-2026-55477
Mitre link : CVE-2026-55477
CVE.ORG link : CVE-2026-55477
JSON object : View
Products Affected
No product.
CWE
CWE-73
External Control of File Name or Path
