CVE-2026-104069: HortusFox < 6.2 Remote Code Execution via Theme Import
HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it under the themes directory to execute arbitrary OS commands as the web-server user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HortusFoxto a version that resolves this vulnerability.Fixed in 6.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated HortusFox administrator can exploit it. The attack requires access to the theme import functionality and the ability to upload a crafted ZIP archive.
What does successful exploitation allow?
A crafted theme archive can place a PHP file and an .htaccess file in the public themes directory. The attacker can then request the uploaded PHP file to execute arbitrary operating-system commands as the web-server user.
Are installations running version 6.2 affected?
The issue affects HortusFox versions before 6.2. The provided information identifies 6.2 as the release containing the fix.