CVE-2026-35482

Source
https://cve.org/CVERecord?id=CVE-2026-35482
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35482.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-35482
Aliases
  • GHSA-3w8f-mcf6-cm7h
Published
2026-06-02T22:50:40.435Z
Modified
2026-07-23T03:56:15.408617783Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
alf.io has an Authenticated RCE via Extension Script Sandbox Escape
Details

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script engine allows an authenticated administrator to execute arbitrary operating system commands on the server. The extension system is intended to execute restricted JavaScript in a sandboxed Rhino environment; however, a combination of an unguarded injected Java object (returnClass) and an incomplete AST blocklist allows the sandbox to be fully escaped using Java reflection without triggering any validation errors. Version 2.0-M5-2606 patches the issue.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35482.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/alfio-event/alf.io

Affected ranges

Type
GIT
Repo
https://github.com/alfio-event/alf.io
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.0-M5-2606"
        }
    ]
}

Affected versions

1.*
1.10
1.10-RC1
1.10-RC2
1.10.1
1.11
1.12
1.12-RC1
1.12-RC2
1.12-RC3
1.12-RC4
1.13
1.13-RC1
1.13-RC2
1.13-RC3
1.14
1.14-RC1
1.14-RC2
1.14.1
1.4
1.4-RC2
1.4.1
1.5
1.6
1.7
1.8
1.8-RC1
1.8-RC2
1.9
1.9.1
2.*
2.0-M0
2.0-M1
2.0-M1-1906
2.0-M1-1906.1
2.0-M2
2.0-M3
2.0-M4
2.0-M4-2204
2.0-M4-2301
2.0-M4-2304
2.0-M4.RC1
2.0-M4.RC2
2.0-M4.RC3
2.0-M4.RC4
2.0-M5
2.0-M5-2502
2.0-M5-2509
alfio-1.*
alfio-1.1
alfio-1.2
alfio-1.3
alfio-1.3-beta1
alfio-1.3.1
v1.*
v1.0-pre-rename
v1.0-pre-rename-v2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35482.json"