Executive brief
x-ui is a web-based management panel for proxy services that allows administrators to configure and monitor Xray proxy instances. The management interface unsafely reflects request URIs into client-side template expressions in the sidebar menu. A logged-in administrator visiting a crafted link could have arbitrary JavaScript executed in their browser session, allowing attackers to steal session data, modify proxy configurations, or abuse the administrator's permissions without their knowledge.
Technical details
The vulnerability is a reflected XSS (CWE-79) caused by improper output encoding: the server applies only HTML entity escaping to the request URI before inserting it into a client-side framework binding expression. The browser decodes entities before the framework evaluates the content as JavaScript, allowing unescaped script execution. Exploitation requires a logged-in user to visit an attacker-controlled URL, enabling data theft and unauthorized actions within the panel's same-origin context.
Affected products
- vaxilu x-ui 0.3.2
Timeline
- 2026-09-22: disclosed: Public disclosure via NVD
- 2026-08-04: other: Advisory report date