{"id":"CVE-2026-61343","summary":"LibreBooking path traversal","details":"LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0.","modified":"2026-08-12T03:51:25.457435166Z","published":"2026-07-09T17:46:05.221Z","database_specific":{"cwe_ids":["CWE-23"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61343.json","cna_assigner":"cisa-cg"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61343.json"},{"type":"ADVISORY","url":"https://github.com/LibreBooking/librebooking/releases/tag/v5.1.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61343"},{"type":"ADVISORY","url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-01.json"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-61343"},{"type":"FIX","url":"https://github.com/LibreBooking/librebooking/commit/cb9b7ad9da0243bd105809f6a4a8a6b9147c71ea"},{"type":"FIX","url":"https://github.com/LibreBooking/librebooking/pull/1456"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/librebooking/librebooking","events":[{"introduced":"0"},{"fixed":"cb9b7ad9da0243bd105809f6a4a8a6b9147c71ea"},{"fixed":"498357b4336d7d534a56b9db3b1c0bf0360efeec"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"5.1.0"}]}}],"versions":["v5.0.3","v5.0.2","v5.0.1","v5.0.0","v4.3.0","v4.2.0","v4.1.0","v4.0.0","v3.0.3","v3.0.2","v3.0.1","v3.0.0","v2.8.6.2","2.8.6.2","v2.8.6.1","2.8.6.1","v2.8.6","2.8.6","v2.8.5.4","2.8.5.4","v2.8.5.3","2.8.5.3","v2.8.5.2","2.8.5.2","v2.8.5.1","2.8.5.1","v2.8.5.1-RC1","2.8.5.1-RC1","v2.8.5","2.8.5","v2.8.4","2.8.4","v2.8.2","2.8.2","v2.8.1","2.8.1","v2.7.8","2.7.8","v2.7.6","2.7.6","v2.7.1","2.7.1","v2.6","2.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61343.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}