Unauthenticated Server-Side Request Forgery (SSRF) in Manager Desktop and Server Editions .
CVE
CVE-2025-54122
Product
Manager Desktop and Server Edition
Published
7/21/2025
Researcher
Krishna Agarwal
Summary
A critical unauthenticated server-side request forgery (SSRF) vulnerability was identified in the proxy handler component of Manager Desktop and Manager Server editions up to version 25.7.18.2519. The flaw allows a remote attacker to coerce the application into issuing arbitrary HTTP requests to internal or otherwise restricted resources, including localhost services and cloud metadata endpoints, fully bypassing network isolation controls. By abusing automatic HTTP redirect handling that downgrades POST requests to GET, an attacker can read sensitive internal data without authentication. Successful exploitation may lead to credential disclosure, internal network reconnaissance, data exfiltration, and broader compromise of cloud or on-prem environments.
Proof of Concept
POC will be released after February 2026
Remediation
This vulnerability has been addressed in Manager Desktop and Server editions Version 25.7.21 and later.