Wallos 是一款开源、可自托管的个人订阅追踪工具。在版本 4.9.6 之前,POST 请求 会从 POST 请求体中接受 和 参数,且未进行任何 SSRF(服务端请求伪造)验证。随后 PHPMailer 会连接到攻击者指定的主机:端口。其他所有通知端点均使用了 进行 SSRF 防护,但邮件通知端点被遗漏。任何已认证的用户均可利用此漏洞探测内部网络及云元数据服务。该问题已在版本 4.9.6 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61640 | 8.5 HIGH | Wallos: SSRF via OIDC Token/UserInfo URL Configuration |
| CVE-2026-61639 | 8.5 HIGH | Wallos: Zip Slip path traversal in database restore writes files to webroot |
| CVE-2026-54600 | 8.2 HIGH | Wallos: Unauthenticated database replacement via import endpoint on fresh install |
| CVE-2026-61641 | 8.1 HIGH | Wallos: OIDC account takeover via email-based account linking without `email_verified` che |
| CVE-2026-54598 | 7.5 HIGH | Missing Authentication for Critical Function in wallos |
| CVE-2026-54599 | 7.5 HIGH | Wallos: OIDC state parameter never validated — login CSRF / account takeover |
| CVE-2026-50199 | 4.3 MEDIUM | Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh |
| CVE-2026-50198 | 4.3 MEDIUM | Wallos: Cross-user subscription cost inference via replacement_subscription_id |
No comments yet