{ "schema_version": "1.4.0", "id": "GHSA-28f5-38xr-jh2w", "modified": "2026-07-28T14:26:53Z", "published": "2026-07-28T14:26:53Z", "aliases": [ "CVE-2026-43910" ], "summary": "java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor", "details": "## Summary\n\nWhen `directConnect(true)` is enabled, appium/java-client unconditionally\naccepts `directConnectHost`, `directConnectPort`, and `directConnectPath`\nfrom the server's NEW_SESSION response and silently redirects all subsequent\nsession traffic to the attacker-specified endpoint — with no allowlist,\nno host validation, and no user notification.\n\n## Affected Code\n\n- `AppiumCommandExecutor.java` (line 196–219): `setDirectConnect()` builds\n a new URL from server-supplied fields and calls `overrideServerUrl(newUrl)`\n without validating host/IP.\n- `DirectConnect.java`: `getUrl()` constructs `protocol://host:port/path`\n with no allowlist.\n\n## Root Cause\n\nOnly the protocol is validated (must equal \"https\"). The destination host\nand port are never checked against any allowlist or denylist.\n\n## PoC (confirmed)\n\nA rogue server injecting `directConnectHost=127.0.0.1:4443` causes the\nclient to silently redirect all post-session commands:\n\n[bootstrap] POST /wd/hub/session\n[bootstrap] Injecting directConnect -> https://127.0.0.1:4443/wd/hub\n[redirect-target] HIT #1: GET /wd/hub/session/poc-session-001/source\n[redirect-target] HIT #2: DELETE /wd/hub/session/poc-session-001\n\nOriginal source code unmodified — confirmed via `git diff HEAD` (empty).\n\n## Evidence Screenshots\n\n**Screenshot 1 — Rogue server capturing redirected traffic:**\n\n\"1\"\n\n**Screenshot 2 — Java client processing response from attacker host:**\n\n\"2\"\n\n## Impact\n\n- Full interception of session traffic\n- Network pivot to internal hosts (RFC-1918, 169.254.169.254)\n- Cloud credential theft via IMDS endpoint\n- Escalates to ~8.1 High in CI/CD environments where directConnect(true)\n is set in shared base configuration\n\n## Suggested Fix\n\nAdd allowlist validation before `overrideServerUrl()` is called, and/or\nblock RFC-1918/loopback/link-local destinations by default.\n\n[poc_appium_directconnect.zip](https://github.com/user-attachments/files/26472525/poc_appium_directconnect.zip)", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" } ], "affected": [ { "package": { "ecosystem": "Maven", "name": "io.appium:java-client" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "8.2.1" }, { "fixed": "10.1.1" } ] } ], "database_specific": { "last_known_affected_version_range": "<= 10.1.0" } } ], "references": [ { "type": "WEB", "url": "https://github.com/appium/java-client/security/advisories/GHSA-28f5-38xr-jh2w" }, { "type": "WEB", "url": "https://github.com/appium/java-client/pull/2408" }, { "type": "WEB", "url": "https://github.com/appium/java-client/commit/2b9cd442b9dbf56ccc6f1e83aeeb411c0ec230c9" }, { "type": "PACKAGE", "url": "https://github.com/appium/java-client" }, { "type": "WEB", "url": "https://github.com/appium/java-client/releases/tag/v10.1.1" } ], "database_specific": { "cwe_ids": [ "CWE-441", "CWE-918" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2026-07-28T14:26:53Z", "nvd_published_at": null } }