PT-2026-6064 · Bolo Blog+1 · Bolo-Blog+1

Maoqiu

·

Published

2026-02-03

·

Updated

2026-03-03

·

CVE-2026-1812

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bolo-blog bolo-solo versions up to 2.6.4
Description A path traversal issue exists due to the manipulation of the File argument within the importFromCnblogs() function located in the src/main/java/org/b3log/solo/bolo/prop/BackupService.java file of the Filename Handler component. This allows for remote exploitation. The details of the exploit have been publicly disclosed. The project maintainers were notified of the issue but have not yet responded.
Recommendations Versions prior to 2.6.4 should be used. As a temporary workaround, consider restricting access to the importFromCnblogs() function until a patch is available.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-1812

Affected Products

Bolo-Blog
Bolo-Solo