NONE · 0

CVE-2026-61639

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ seque...

Vulnerability Description

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads crafted zip with entry logos/../../endpoints/shell.php to write webshell to webroot. Extension filter only applies to post-extraction logo copy step. This issue has been patched in version 4.9.6.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-61639?

CVE-2026-61639 is a documented vulnerability. Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ seque...

How severe is CVE-2026-61639?

CVSS scoring is not yet available for CVE-2026-61639. Check NVD for updates.

Is there a patch for CVE-2026-61639?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.