Server-Side Request Forgery in Transmute Tool by Transmute App
CVE-2026-54054

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-54054?

Transmute, an open-source file conversion and compression tool, has a vulnerability in its URL import endpoint, allowing user-supplied URLs to be fetched without validating their resolution to public addresses. This flaw could enable authenticated users to manipulate the server into making internal requests, leading to potential exposure of sensitive internal resources. The issue has been addressed in version 1.3.0, which restricts such unauthorized access.

Affected Version(s)

transmute < 1.3.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.