hackmd.io High-Risk CVE-2026-108101: Unrestricted File Upload in HortusFox
Article Content
- •CVE-2026-108101 allows file uploads leading to stored XSS.
- •Affected versions of HortusFox are up to 6.3.
- •Immediate action is required to mitigate risks from this vulnerability.
HortusFox versions up to 6.3 have an unrestricted file upload vulnerability (CVE-2026-108101) in the PlantAttachmentModel. This flaw allows authenticated users to upload potentially malicious files, such as HTML or SVG, which can lead to stored cross-site scripting (XSS) attacks. Attackers can exploit this by uploading files that execute JavaScript when accessed by other users. The vulnerability poses a high operational concern, especially for self-hosted deployments accessible by untrusted users. Mitigations include restricting uploads to trusted users and applying vendor patches as soon as they are available. The CVE was published on 2026-10-09 with a CVSS score of 7.7, indicating a high severity level. Current exploitation status remains unclear, and no specific threat intelligence has been provided.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-108101 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of HortusFox are affected?
What are the risks associated with this vulnerability?
What immediate actions should be taken?
Continue Reading
Twitch Chat Messages Exploit OBS Studio via Chromium Vulnerability A vulnerability in OBS Studio allows malicious Twitch chat messages to execute native code on streamers' Windows PCs. This exploit targets users running OBS Studio version 32.2.2 or older, leveraging a cross-site scripting (XSS) flaw in custom overlays that render viewer messages as unsanitized HTML. The attack…