PT-2026-6063 · Bolo Blog+1 · Bolo-Blog+1

Maoqiu

·

Published

2026-02-03

·

Updated

2026-03-03

·

CVE-2026-1811

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bolo-blog bolo-solo versions up to 2.6.4
Description A path traversal issue exists in the Filename Handler component of bolo-blog bolo-solo. The issue is located in the importFromMarkdown function within the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java. Manipulation of the File argument can lead to path traversal, potentially allowing remote exploitation. The exploit has been published.
Recommendations Versions prior to 2.6.4 are vulnerable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-1811

Affected Products

Bolo-Blog
Bolo-Solo