CVE-2026-28507
Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained import file write and template path traversal. This issue has been patched in version 1.6.4.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/idno/idno/releases/tag/1.6.4, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28507.json, https://github.com/idno/idno/security/advisories/GHSA-37j7-56xc-c468, https://nvd.nist.gov/vuln/detail/CVE-2026-28507