CVE-2025-54122
Unauthenticated Server-Side Request Forgery (SSRF) in Manager Desktop and Server Editions .
A critical unauthenticated server-side request forgery (SSRF) vulnerability was identified in the proxy handler component of Manager Desktop and Manager Server editions up to version 25.7.18.2519. The flaw allows a remote attacker to coerce the application into issuing arbitrary HTTP requests to internal or otherwise restricted resources, including localhost services and cloud metadata endpoints, fully bypassing network isolation controls. By abusing automatic HTTP redirect handling that downgrades POST requests to GET, an attacker can read sensitive internal data without authentication. Successful exploitation may lead to credential disclosure, internal network reconnaissance, data exfiltration, and broader compromise of cloud or on-prem environments.
Identifier
CVE-2025-54122
Affected product
Manager Desktop and Server Edition
Disclosed
Jul 21, 2025
Credit
Krishna Agarwal
Proof of Concept
Remediation
Running this software?
If Manager Desktop and Server Edition is in your environment, the reproduction steps above are enough to verify exposure yourself. If you would rather have the same class of bug hunted across your own stack, that is what we do as an engagement.