CVE-2026-30828: Wallos: SSRF via url parameter leading to File Traversal
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system files. This issue has been patched in version 4.6.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wallosto a version that resolves this vulnerability.Fixed in 4.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30828?
CVE-2026-30828 is classified as a high severity vulnerability due to potential local file retrieval and exposure.
How do I fix CVE-2026-30828?
To fix CVE-2026-30828, upgrade to Wallos version 4.6.2 or later.
What effects does CVE-2026-30828 have on Wallos?
CVE-2026-30828 allows an attacker to perform SSRF, potentially leading to local file traversal.
What versions of Wallos are affected by CVE-2026-30828?
All versions of Wallos prior to 4.6.2 are affected by CVE-2026-30828.
Is CVE-2026-30828 exploitable remotely?
Yes, CVE-2026-30828 can be exploited remotely if the application is accessible over the network.