Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/mhsanaei/3x-ui/v3
  4. ›
  5. CVE-2026-55477

CVE-2026-55477: 3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

August 24, 2026

An authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be leveraged to obtain code execution and persistent access as the user running Xray (including root when Xray is running as root).

References

  • github.com/MHSanaei/3x-ui/commit/80e168787ed608e83a065033ee94c8bfc3025ce7
  • github.com/MHSanaei/3x-ui/releases/tag/v3.3.1
  • github.com/MHSanaei/3x-ui/security/advisories/GHSA-jm48-m3rr-9hgg
  • github.com/advisories/GHSA-jm48-m3rr-9hgg
  • nvd.nist.gov/vuln/detail/CVE-2026-55477

Code Behaviors & Features

Detect and mitigate CVE-2026-55477 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.3.1

Fixed versions

  • 3.3.1

Solution

Upgrade to version 3.3.1 or above.

Impact 7.2 HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-20: Improper Input Validation
  • CWE-73: External Control of File Name or Path

Source file

go/github.com/mhsanaei/3x-ui/v3/CVE-2026-55477.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 22 Sep 2026 12:21:42 +0000.