PT-2026-6062 · Unknown · Bolo-Blog Bolo-Solo

Maoqiu

·

Published

2026-02-03

·

Updated

2026-03-03

·

CVE-2026-1810

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bolo-blog bolo-solo versions prior to 2.6.5
Description A path traversal issue exists in the ZIP File Handler component of bolo-blog bolo-solo. The issue is located in the unpackFilteredZip function within the src/main/java/org/b3log/solo/bolo/prop/BackupService.java file. Manipulating the File argument can lead to path traversal, and the attack can be carried out remotely. The exploit is publicly available. The project was notified of the issue but has not yet responded.
Recommendations Update bolo-blog bolo-solo to version 2.6.5 or later. As a temporary workaround, restrict access to the unpackFilteredZip function until a patch is available.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1810

Affected Products

Bolo-Blog Bolo-Solo