THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jm48-m3rr-9hgg (high) — 3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

[GHSA] GHSA-jm48-m3rr-9hgg (high) — 3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

medgithub_advisoriesPublished 2026-08-24

GHSA-jm48-m3rr-9hgg Severity: high CVE: CVE-2026-55477

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

# Summary

An authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be leveraged to obtain code executi

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jm48-m3rr-9hgg