Wallos 是一款开源、可自托管的个人订阅管理工具。在 4.0.0 至 4.9.6 之前,Wallos 的 OIDC 登录功能仅通过匹配邮箱声明(email claim)将传入的 OIDC 身份关联到现有的本地账户,而未验证身份提供商(IdP)是否已核实该邮箱(email_verified)。当 Wallos 配置对接的 IdP 允许用户提交任意或未经核实的邮箱(例如多租户 IdP、支持开放自助注册的 IdP,或攻击者部分可控的 IdP)时,没有 Wallos 账户的攻击者可以使用管理员的邮箱进行身份认证,从而以
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61640 | 8.5 HIGH | Wallos: SSRF via OIDC Token/UserInfo URL Configuration |
| CVE-2026-61639 | 8.5 HIGH | Wallos: Zip Slip path traversal in database restore writes files to webroot |
| CVE-2026-54600 | 8.2 HIGH | Wallos: Unauthenticated database replacement via import endpoint on fresh install |
| CVE-2026-61638 | 8.2 HIGH | Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port |
| CVE-2026-54598 | 7.5 HIGH | Missing Authentication for Critical Function in wallos |
| CVE-2026-54599 | 7.5 HIGH | Wallos: OIDC state parameter never validated — login CSRF / account takeover |
| CVE-2026-50199 | 4.3 MEDIUM | Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh |
| CVE-2026-50198 | 4.3 MEDIUM | Wallos: Cross-user subscription cost inference via replacement_subscription_id |
No comments yet