PatchSiren

transmute-app CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM transmute-app CVE published 2026-09-10

CVE-2026-54054

CVE-2026-54054 is a Server-Side Request Forgery (SSRF) vulnerability in Transmute, a free, open-source, self-hosted file conversion and compression tool. The vulnerability exists in the URL import endpoint, `POST /api/files/url`, which allows an authenticated user to cause the Transmute server to make HTTP requests to internal or cloud-local resources. This issue can result in full-read SSRF, allowing the [truncated]