GHSA-rr49-f9g6-c9r5

Suggest an improvement
Source
https://github.com/advisories/GHSA-rr49-f9g6-c9r5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rr49-f9g6-c9r5/GHSA-rr49-f9g6-c9r5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rr49-f9g6-c9r5
Aliases
Published
2026-09-23T13:55:47Z
Modified
2026-09-23T14:00:05Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
Details

Impact

The Classic portlet (plone.app.portlets.portlets.classic) used its user-supplied template/macro fields to build a TALES path expression that was then evaluated by the TAL path() helper. Because the value was interpreted as a full TALES expression, a user able to add or edit a Classic portlet could supply a crafted value that escapes simple path traversal and is evaluated as arbitrary code.

This is exploitable by any authenticated user who can configure a Classic portlet - which, with the default role map, includes regular users on their personal dashboard. The result is code execution in the context of the Plone process, i.e. a privilege escalation across the trust boundary between an authenticated web user and the server-side process.

Patches

The problem has been patched in plone.app.portlets

  • For Plone 6.2, upgrade to plone.app.portlets 7.0.2.
  • For Plone 6.1, upgrade to plone.app.portlets 6.0.4.
  • For Plone 6.0, upgrade to plone.app.portlets 5.0.8.

Workarounds

If upgrading is not immediately possible:

  • Restrict who can manage portlets: remove the plone.app.portlets.ManageOwnPortlets permission from untrusted roles, and limit Manage portlets to trusted administrators (usually this is already restricted to the Manager and Site Administrator roles).
  • Where the Classic portlet is not needed, unregister it so it cannot be added. This would need to be done by editing a portlets.xml in your own code, so it is not a quick fix.
  • You could also effectively disable showing the classic portlet by customising its template. In the Zope Management Interface go to the portal_view_customizations tool, locate the classic.pt template and click it. Click the Customize button. Remove all text and replace it with <div>The classic portlet was disabled.</div>. (This is not a recommended way of customising a template, but in this case it is quite effective.)

Credits

Discovered by Giuseppe Caruso, and reported to the Plone/Zope Security Team. Thanks!

Database specific
{
    "cwe_ids":  [
        "CWE-95"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-23T13:55:47Z",
    "nvd_published_at":  "2026-09-22T19:16:43Z",
    "severity":  "CRITICAL"
}
References

Affected packages

PyPI / plone-app-portlets

Package

Name
plone-app-portlets
View open source insights on deps.dev
Purl
pkg:pypi/plone-app-portlets

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.0.2

Affected versions

7.*
7.0.0
7.0.1

Database specific

last_known_affected_version_range
"<= 7.0.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rr49-f9g6-c9r5/GHSA-rr49-f9g6-c9r5.json"

PyPI / plone-app-portlets

Package

Name
plone-app-portlets
View open source insights on deps.dev
Purl
pkg:pypi/plone-app-portlets

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.0.4

Affected versions

6.*
6.0.0
6.0.1
6.0.2
6.0.3

Database specific

last_known_affected_version_range
"<= 6.0.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rr49-f9g6-c9r5/GHSA-rr49-f9g6-c9r5.json"

PyPI / plone-app-portlets

Package

Name
plone-app-portlets
View open source insights on deps.dev
Purl
pkg:pypi/plone-app-portlets

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.0.8

Affected versions

5.*
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7

Database specific

last_known_affected_version_range
"<= 5.0.7"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rr49-f9g6-c9r5/GHSA-rr49-f9g6-c9r5.json"