PT-2026-23823 · Wallos · Wallos

4Rdr

·

Published

2026-03-07

·

Updated

2026-03-12

·

CVE-2026-30828

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.6.2
Description Wallos is a self-hostable personal subscription tracker. Versions prior to 4.6.2 contain an issue where the url parameter can be exploited to retrieve local system files.
Recommendations Update to version 4.6.2 or later.

Exploit

Fix

Path traversal

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-30828
GHSA-P7QJ-669R-GRVC

Affected Products

Wallos