Executive brief
Tarzan-CMS is a Java-based open-source content management system used for building websites and blogs. The theme download feature fails to properly validate URLs, combined with an authentication bypass in the Shiro access control configuration, allowing unauthenticated attackers to make arbitrary HTTP requests from the server to internal networks or external systems. This could enable reconnaissance of internal infrastructure, data exfiltration, or attacks on internal services.
Technical details
The vulnerability is a server-side request forgery (SSRF) in the ThemeService.java openConnection method (line 177), affecting the theme download functionality. Root cause: (1) Shiro filter chain misconfiguration where the `/theme/*` path is marked as anonymous ("anon") before permission checks, completely bypassing authentication for all theme management endpoints, and (2) insufficient validation of the httpUrl parameter—only basic regex filtering is performed, allowing attackers to bypass restrictions via DNS rebinding to access internal IP addresses. An unauthenticated attacker can directly call the /theme/download endpoint with a malicious httpUrl parameter to force the server to make HTTP requests to internal or external targets. The project was informed but has not yet responded with a patch.
Affected products
- Taisan Tarzan-CMS 1.0.0
Timeline
- 2026-08-07: disclosed: Vulnerability reported via Gitee issue #IK768M
- 2026-09-14: advisory: CVE-2026-90710 published on NVD