Junglewise Threat Intelligence

CVE-2026-55477: MHSanaei 3X-UI arbitrary file write via Xray log path manipulation

CVE-2026-55477 · Severity: high · CVSS 7.2 · Published 2026-06-25

Vendors: Go.

Executive brief

3X-UI is a panel for managing Xray proxy configurations. An authenticated administrator can manipulate the Xray log path configuration through database import to write arbitrary files to the system, potentially achieving code execution or persistent access. If Xray runs as root, this leads to complete system compromise.

Technical details

The vulnerability exists in the database import functionality which fails to validate Xray configuration values, specifically `xrayTemplateConfig.log.access` and `xrayTemplateConfig.log.error` paths. An authenticated admin can export the SQLite database, modify the log paths to arbitrary locations (e.g., `~/.ssh/authorized_keys`), inject controlled content via the inbound client's email field, and re-import the database. When Xray processes connections, it writes logs to the attacker-controlled path with attacker-controlled content, resulting in arbitrary file write as the Xray process user. The fix in v3.3.1 restricts log paths to the panel's log folder via `resolveXrayLogPaths()`, stripping absolute paths and `..` traversal sequences. Attack requires high-privilege admin access and no user interaction.

Affected products

  • MHSanaei 3X-UI v3 <= 3.3.0; v2 <= 2.9.4

Timeline

  • 2026-06-12: disclosed: Published to GitHub Advisory Database
  • 2026-08-24: patched: Fixed in v3.3.1

References