CVE-2026-30828
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system files. This issue has been patched in version 4.6.2.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/ellite/Wallos/releases/tag/v4.6.2, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30828.json, https://github.com/ellite/Wallos/security/advisories/GHSA-p7qj-669r-grvc, https://nvd.nist.gov/vuln/detail/CVE-2026-30828, https://github.com/ellite/Wallos/commit/e8a513591dbbf885966e2ef55c38622785b9060d
