Executive brief
ThingsBoard, an open-source IoT platform used for device management and data visualization, contains a security flaw in its image upload feature. An attacker can upload a specially crafted image file that forces the server to make unauthorized requests to internal systems or external websites. This could allow an attacker to bypass network security controls, access sensitive internal data, or probe private infrastructure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in ThingsBoard versions prior to 4.2.1 within the dashboard's Image Upload Gallery feature. The vulnerability is rooted in the improper handling of SVG files; an attacker can upload a malicious SVG containing external references that the server-side parser attempts to resolve. This allows an unauthenticated or low-privileged attacker to initiate outbound network requests from the server's context. This can be leveraged to access internal metadata services, scan internal networks, or interact with other internal resources not exposed to the public internet. The issue was addressed in version 4.2.1 by implementing a Content-Security-Policy (CSP) header and improving image processing.
Affected products
- ThingsBoard, Inc. ThingsBoard < 4.2.1
Timeline
- 2025-08-27: patched: Initial patch submitted via pull request
- 2025-10-15: patched: Version 4.2.1 released
- 2025-10-17: advisory: CVE-2025-34282 published