CVE-2026-28507

HIGH

Idno <1.6.4 - Remote Code Execution

Title source: llm
STIX 2.1

Description

Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained import file write and template path traversal. This issue has been patched in version 1.6.4.

References (2)

Core 2
Core References
Release Notes x_refsource_misc
https://github.com/idno/idno/releases/tag/1.6.4

Scores

CVSS v3 7.2
EPSS 0.0067
EPSS Percentile 47.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
idno/known 0 - 1.6.4Packagist
withknown/known < 1.6.4
Published Mar 06, 2026
Tracked Since Mar 06, 2026