SSRF Vulnerability in Wallos Personal Subscription Tracker
CVE-2026-77351
3.5LOW
What is CVE-2026-77351?
Wallos, an open-source personal subscription tracker, contains a vulnerability that allows any authenticated user to store arbitrary SMTP hosts in their email notification settings without proper server-side validation. This oversight permits low-privileged attackers to craft malicious SMTP hosts leading to unwanted outbound connections from the Wallos server. The implications of this vulnerability are significant, as it could allow attackers to probe internal network services, potentially exposing sensitive data or systems. The issue is resolved in version 5.0.0, where appropriate validation measures have been implemented.
Affected Version(s)
Wallos < 5.0.0
