Xray panel supporting multi-protocol multi-user expire day & traffic & ip limit (Vmess & Vless & Trojan & ShadowSocks & Wireguard)
Find a file
Sanaei 46d9a0e8cf
Some checks are pending
CodeQL Advanced / Analyze (go) (push) Waiting to run
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
Release 3X-UI / Analyze Go code (push) Waiting to run
Release 3X-UI / build (386) (push) Blocked by required conditions
Release 3X-UI / build (amd64) (push) Blocked by required conditions
Release 3X-UI / build (arm64) (push) Blocked by required conditions
Release 3X-UI / build (armv5) (push) Blocked by required conditions
Release 3X-UI / build (armv6) (push) Blocked by required conditions
Release 3X-UI / build (armv7) (push) Blocked by required conditions
Release 3X-UI / build (s390x) (push) Blocked by required conditions
Release 3X-UI / Build for Windows (push) Blocked by required conditions
Add SSRF protection (#4044)
* Add SSRF protection for custom geo downloads

Introduce SSRF-safe HTTP transport for custom geo operations by adding ssrfSafeTransport and isBlockedIP helpers. The transport resolves hosts and blocks loopback, private, link-local and unspecified addresses, returning ErrCustomGeoSSRFBlocked on violations. Update probeCustomGeoURLWithGET, probeCustomGeoURL and downloadToPathOnce to use the safe transport. Also add the new error ErrCustomGeoSSRFBlocked and necessary imports. Minor whitespace/formatting adjustments in subClashService.go, web/entity/entity.go and web/service/setting.go.

* Add path traversal protection for custom geo

Prevent path traversal when handling custom geo downloads by adding ErrCustomGeoPathTraversal and a validateDestPath() helper that ensures destination paths stay inside the bin folder. Call validateDestPath from downloadToPathOnce, Update and Delete paths and wrap errors appropriately. Reconstruct sanitized URLs in sanitizeURL to break taint propagation before use. Map the new path-traversal error to a user-facing i18n message in the controller.

* fix
2026-04-20 00:10:02 +02:00
.github Add CodeQL Advanced GitHub Actions workflow 2026-04-19 23:39:10 +02:00
.vscode DevTools 2025-10-02 01:47:12 +02:00
config v2.8.11 2026-03-04 13:54:01 +01:00
database Add custom geosite/geoip URL sources (#3980) 2026-04-19 21:24:24 +02:00
logger feat: add file logger support (#3575) 2025-10-09 17:39:29 +02:00
media donate: nowpayments 2025-09-18 20:14:10 +02:00
sub Add SSRF protection (#4044) 2026-04-20 00:10:02 +02:00
util fix windows build 2026-02-20 02:07:46 +01:00
web Add SSRF protection (#4044) 2026-04-20 00:10:02 +02:00
windows_files Update OpenSSL installer to version 3.6.0 2026-01-05 18:49:30 +01:00
xray Add url speed test for outbound (#3767) 2026-02-09 21:43:17 +01:00
.env.example fix: display of outbound traffic (#3604) 2025-12-23 15:43:25 +01:00
.gitignore Moved DB to same app folder on Windows (#3340) 2025-08-13 23:19:59 +02:00
CONTRIBUTING.md fix: display of outbound traffic (#3604) 2025-12-23 15:43:25 +01:00
docker-compose.yml fix: enhance WebSocket stability, resolve XHTTP configurations and fix UI loading shifts (#3997) 2026-04-19 21:01:00 +02:00
DockerEntrypoint.sh chore: X_UI_ENABLE_FAIL2BAN -> XUI_ENABLE_FAIL2BAN (#3030) 2025-05-22 08:21:23 +02:00
Dockerfile Bump Go to 1.26 2026-02-16 01:10:43 +01:00
DockerInit.sh Xray Core v26.2.6 and dependency updates 2026-02-09 12:49:32 +01:00
go.mod feat add clash yaml convert (#3916) 2026-04-19 22:26:13 +02:00
go.sum Bump Go and dependency versions 2026-04-01 13:47:27 +02:00
install.sh fix: enhance WebSocket stability, resolve XHTTP configurations and fix UI loading shifts (#3997) 2026-04-19 21:01:00 +02:00
LICENSE 3x-ui 2023-02-09 22:48:06 +03:30
main.go fix windows build 2026-02-20 02:07:46 +01:00
README.ar_EG.md Add custom geosite/geoip URL sources (#3980) 2026-04-19 21:24:24 +02:00
README.es_ES.md Add custom geosite/geoip URL sources (#3980) 2026-04-19 21:24:24 +02:00
README.fa_IR.md Add custom geosite/geoip URL sources (#3980) 2026-04-19 21:24:24 +02:00
README.md Add custom geosite/geoip URL sources (#3980) 2026-04-19 21:24:24 +02:00
README.ru_RU.md Add custom geosite/geoip URL sources (#3980) 2026-04-19 21:24:24 +02:00
README.zh_CN.md Add custom geosite/geoip URL sources (#3980) 2026-04-19 21:24:24 +02:00
update.sh fix: enhance WebSocket stability, resolve XHTTP configurations and fix UI loading shifts (#3997) 2026-04-19 21:01:00 +02:00
x-ui.rc [feat] restart xray-core from cli #3825 2026-02-20 00:03:16 +01:00
x-ui.service.arch [feat] restart xray-core from cli #3825 2026-02-20 00:03:16 +01:00
x-ui.service.debian [feat] restart xray-core from cli #3825 2026-02-20 00:03:16 +01:00
x-ui.service.rhel [feat] restart xray-core from cli #3825 2026-02-20 00:03:16 +01:00
x-ui.sh Fix SSL domain setup on reinstall: reuse existing certs and avoid false success/failure logs (#4004) 2026-04-17 12:19:45 +02:00

English | فارسی | العربية | 中文 | Español | Русский

3x-ui

Release Build GO Version Downloads License Go Reference Go Report Card

3X-UI — advanced, open-source web-based control panel designed for managing Xray-core server. It offers a user-friendly interface for configuring and monitoring various VPN and proxy protocols.

Important

This project is only for personal usage, please do not use it for illegal purposes, and please do not use it in a production environment.

As an enhanced fork of the original X-UI project, 3X-UI provides improved stability, broader protocol support, and additional features.

Custom GeoSite / GeoIP DAT sources

Administrators can add custom GeoSite and GeoIP .dat files from URLs in the panel (same workflow as updating built-in geofiles). Files are stored under the same directory as the Xray binary (XUI_BIN_FOLDER, default bin/) with deterministic names: geosite_<alias>.dat and geoip_<alias>.dat.

Routing: Xray resolves extra lists using the ext: form, for example ext:geosite_myalias.dat:tag or ext:geoip_myalias.dat:tag, where tag is a list name inside that DAT file (same pattern as built-in regional files such as ext:geoip_IR.dat:ir).

Reserved aliases: Only for deciding whether a name is reserved, the panel compares a normalized form of the alias (strings.ToLower, -_). User-entered aliases and generated file names are not rewritten in the database; they must still match ^[a-z0-9_-]+$. For example, geoip-ir and geoip_ir collide with the same reserved entry.

Quick Start

bash <(curl -Ls https://raw.githubusercontent.com/mhsanaei/3x-ui/master/install.sh)

For full documentation, please visit the project Wiki.

A Special Thanks to

Acknowledgment

  • Iran v2ray rules (License: GPL-3.0): Enhanced v2ray/xray and v2ray/xray-clients routing rules with built-in Iranian domains and a focus on security and adblocking.
  • Russia v2ray rules (License: GPL-3.0): This repository contains automatically updated V2Ray routing rules based on data on blocked domains and addresses in Russia.

Support project

If this project is helpful to you, you may wish to give it a🌟

Buy Me A Coffee
Crypto donation button by NOWPayments

Stargazers over Time

Stargazers over time