<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Bug report]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">I submitted a bug report on 2 June, but I haven't received a confirmation yet.</p>
<p dir="auto">Could you please let me know if you received it?<br />
Thanks</p>
]]></description><link>https://forum.cloudron.io/topic/15586/bug-report</link><generator>RSS for Node</generator><lastBuildDate>Sun, 16 Aug 2026 03:56:57 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/15586.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 04 Jun 2026 00:06:46 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Bug report on Fri, 05 Jun 2026 11:42:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dark" aria-label="Profile: dark">@<bdi>dark</bdi></a> thanks for your report. I looked into them. For transparency, here is our assessment.</p>
<p dir="auto">All the reported issues require the attacker to already have an admin token / compromised admin password. All the issues below are not reproducible as a (compromised) normal user. Also. the issues were reproduced on the demo instance, which of course has the admin username/password displayed in public.</p>
<p dir="auto">We found the report to be thorough and with clear explanation on how to reproduce the problems. From our side, we ack the bugs and have made the following fixes:</p>
<p dir="auto">Problem: Full SSRF via applinks. This is about adding an internal IPs as an applink.<br />
Our analysis: Linking to internal apps is a legitimate feature. An applink is fundamentally a bookmark and there's nothing wrong with pointing it at 192.168.1.50 or an internal app. Applinks REST response only returns label and icon not contents of a site. You can't really infiltrate EC2 metadata etc and neither can you make non GET requests.<br />
Our fix: We have added a fix now to block server internal IPs like localhost and docker internal network.</p>
<p dir="auto">Problem: SQL injection via dynamic column names. This is about being able to send arbitrary field names in the REST APIs.<br />
Our analysis: Indeed, our query builders, should only use field names which are in the db and are part of an allow list.<br />
Our fix: We have added allow list to all our model code</p>
<p dir="auto">Problem: 2FA/TOTP BYPASS via skipTotpCheck: true<br />
Our analysis: I think this is because the demo instance does not allow you to set a TOTP. It doesn't show an error currently when this happens and leads the user to believe an OTP was set. For the demo server, we can't allow users to set a TOTP because it will make it unsuable for others.<br />
Our fix: We will show an error like we show in other places. But also, the password login routes have already been removed in Cloudron 10 (which is yet to be released). That route exists as a backward compat for the CLI. Cloudron only supports OIDC device auth for the CLI from Cloudron 10.</p>
<p dir="auto">Problem: Stored XSS via branding footer<br />
Our analysis: right. This issue has been present since ages and our demo instance always has someone putting some alert() or some stupid HTML in there periodically...<br />
Our fix: We give in to the non-stop reports about this... We use dompurify now.</p>
<p dir="auto">Thanks for the report again. Very clear and solid notes. I also took the chance to update <a href="https://www.cloudron.io/security.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cloudron.io/security.html</a> and <a href="https://www.cloudron.io/.well-known/security.txt" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cloudron.io/.well-known/security.txt</a></p>
]]></description><link>https://forum.cloudron.io/post/125533</link><guid isPermaLink="true">https://forum.cloudron.io/post/125533</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Fri, 05 Jun 2026 11:42:00 GMT</pubDate></item><item><title><![CDATA[Reply to Bug report on Thu, 04 Jun 2026 08:20:22 GMT]]></title><description><![CDATA[<p dir="auto">Hello <a class="plugin-mentions-user plugin-mentions-a" href="/user/dark" aria-label="Profile: dark">@<bdi>dark</bdi></a><br />
The team has send you a reply.</p>
]]></description><link>https://forum.cloudron.io/post/125476</link><guid isPermaLink="true">https://forum.cloudron.io/post/125476</guid><dc:creator><![CDATA[james]]></dc:creator><pubDate>Thu, 04 Jun 2026 08:20:22 GMT</pubDate></item><item><title><![CDATA[Reply to Bug report on Thu, 04 Jun 2026 07:51:20 GMT]]></title><description><![CDATA[<p dir="auto">Hello <a class="plugin-mentions-user plugin-mentions-a" href="/user/dark" aria-label="Profile: dark">@<bdi>dark</bdi></a><br />
Thanks for the information.<br />
I will ask the team about some insights and will get back to you.</p>
]]></description><link>https://forum.cloudron.io/post/125473</link><guid isPermaLink="true">https://forum.cloudron.io/post/125473</guid><dc:creator><![CDATA[james]]></dc:creator><pubDate>Thu, 04 Jun 2026 07:51:20 GMT</pubDate></item><item><title><![CDATA[Reply to Bug report on Thu, 04 Jun 2026 07:50:04 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/james" aria-label="Profile: james">@<bdi>james</bdi></a> yes</p>
]]></description><link>https://forum.cloudron.io/post/125472</link><guid isPermaLink="true">https://forum.cloudron.io/post/125472</guid><dc:creator><![CDATA[dark]]></dc:creator><pubDate>Thu, 04 Jun 2026 07:50:04 GMT</pubDate></item><item><title><![CDATA[Reply to Bug report on Thu, 04 Jun 2026 07:49:35 GMT]]></title><description><![CDATA[<p dir="auto">Hello <a class="plugin-mentions-user plugin-mentions-a" href="/user/dark" aria-label="Profile: dark">@<bdi>dark</bdi></a><br />
Is the mail you used in our forum the same you have used to send the mail to <a href="mailto:security@cloudron.io" target="_blank" rel="noopener noreferrer nofollow ugc">security@cloudron.io</a>?</p>
]]></description><link>https://forum.cloudron.io/post/125471</link><guid isPermaLink="true">https://forum.cloudron.io/post/125471</guid><dc:creator><![CDATA[james]]></dc:creator><pubDate>Thu, 04 Jun 2026 07:49:35 GMT</pubDate></item><item><title><![CDATA[Reply to Bug report on Thu, 04 Jun 2026 07:47:53 GMT]]></title><description><![CDATA[<p dir="auto">Hi <a class="plugin-mentions-user plugin-mentions-a" href="/user/james" aria-label="Profile: james">@<bdi>james</bdi></a><br />
I actually sent the email to <a href="mailto:security@cloudron.io" target="_blank" rel="noopener noreferrer nofollow ugc">security@cloudron.io</a> following the instructions on <a href="https://www.cloudron.io/security.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.cloudron.io/security.html</a></p>
<p dir="auto">Since it involves a security vulnerability, I wanted to report it privately rather than posting it here on the public forum.</p>
]]></description><link>https://forum.cloudron.io/post/125470</link><guid isPermaLink="true">https://forum.cloudron.io/post/125470</guid><dc:creator><![CDATA[dark]]></dc:creator><pubDate>Thu, 04 Jun 2026 07:47:53 GMT</pubDate></item><item><title><![CDATA[Reply to Bug report on Thu, 04 Jun 2026 07:43:26 GMT]]></title><description><![CDATA[<p dir="auto">Hello <a class="plugin-mentions-user plugin-mentions-a" href="/user/dark" aria-label="Profile: dark">@<bdi>dark</bdi></a> and welcome to the Cloudron forum</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dark" aria-label="Profile: dark">@<bdi>dark</bdi></a> <a href="/post/125463">said</a>:</p>
<p dir="auto">I submitted a bug report on 2 June, but I haven't received a confirmation yet.</p>
</blockquote>
<p dir="auto">I assume you have sent us a mail at <a href="mailto:support@cloudron.io" target="_blank" rel="noopener noreferrer nofollow ugc">support@cloudron.io</a>?<br />
Bug reports should be submitted in the forum unless they are critical security issues.<br />
So you can use this topic to report this bug here.</p>
]]></description><link>https://forum.cloudron.io/post/125464</link><guid isPermaLink="true">https://forum.cloudron.io/post/125464</guid><dc:creator><![CDATA[james]]></dc:creator><pubDate>Thu, 04 Jun 2026 07:43:26 GMT</pubDate></item></channel></rss>