PYSEC-2026-4138

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/plone-app-portlets/PYSEC-2026-4138.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-4138
Aliases
Published
2026-10-01T16:38:38Z
Modified
2026-10-01T17:45:15Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
Details

Impact

The Classic portlet (plone.app.portlets.portlets.classic) used its user-supplied template/macro fields to build a TALES path expression that was then evaluated by the TAL path() helper. Because the value was interpreted as a full TALES expression, a user able to add or edit a Classic portlet could supply a crafted value that escapes simple path traversal and is evaluated as arbitrary code.

This is exploitable by any authenticated user who can configure a Classic portlet - which, with the default role map, includes regular users on their personal dashboard. The result is code execution in the context of the Plone process, i.e. a privilege escalation across the trust boundary between an authenticated web user and the server-side process.

Patches

The problem has been patched in plone.app.portlets

  • For Plone 6.2, upgrade to plone.app.portlets 7.0.2.
  • For Plone 6.1, upgrade to plone.app.portlets 6.0.4.
  • For Plone 6.0, upgrade to plone.app.portlets 5.0.8.

Workarounds

If upgrading is not immediately possible:

  • Restrict who can manage portlets: remove the plone.app.portlets.ManageOwnPortlets permission from untrusted roles, and limit Manage portlets to trusted administrators (usually this is already restricted to the Manager and Site Administrator roles).
  • Where the Classic portlet is not needed, unregister it so it cannot be added. This would need to be done by editing a portlets.xml in your own code, so it is not a quick fix.
  • You could also effectively disable showing the classic portlet by customising its template. In the Zope Management Interface go to the portal_view_customizations tool, locate the classic.pt template and click it. Click the Customize button. Remove all text and replace it with <div>The classic portlet was disabled.</div>. (This is not a recommended way of customising a template, but in this case it is quite effective.)

Credits

Discovered by Giuseppe Caruso, and reported to the Plone/Zope Security Team. Thanks!

References

Affected packages

PyPI / plone-app-portlets

Package

Name
plone-app-portlets
View open source insights on deps.dev
Purl
pkg:pypi/plone-app-portlets

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.0.8
Introduced
6.0.0
Fixed
6.0.4
Introduced
7.0.0
Fixed
7.0.2
Introduced
5.0.0
Fixed
5.0.8

Affected versions

5.*
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
6.*
6.0.0
6.0.1
6.0.2
6.0.3
7.*
7.0.0
7.0.1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/plone-app-portlets/PYSEC-2026-4138.yaml"