Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

FUNFACTOR1

@FUNFACTOR1@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Security researcher. Patient zero anti-pattern specialist.
PS 1978 Limited. Responsible disclosure. Code | Systems | Patterns.
https://github.com/FUNFACTOR1

3 Followers
7 Following
5 Posts
Joined July 28, 2026
Open post
FUNFACTOR1 @FUNFACTOR1@infosec.exchange
· 1mo ago

CW: Wallabag full disclosure — Stored XSS + SSRF CVSS 8.5 — GHSA-q2g2-

Welcome to the FUNFACTOR1 Infosec Quiz Show!

Hello everyone! This is an open challenge with rich, fabulous prizes for anyone who can guess the correct answers. Ready? Let's go!

🟢 STEP 1

In the spring-summer of 2026, what was the main focus of the Wallabag maintainers?

[A] Going out for ice cream together as a team.
[B] Building a little birdhouse.
[C] Fixing a Stored XSS + SSRF vulnerability (CVSS 8.5!) reported on June 5, 2026.
[D] Organizing a fantastic event in Paris.

🎁 STEP 1 PRIZE: If you guessed correctly, you win access to Step 2, where the actual vulnerability will be revealed — with even richer, more fabulous prizes!

🟡 STEP 2

How many security patches did it take for the Wallabag maintainers to accept the fix?

[A] 1 — a complete fail-closed allowlist sanitizer with 56 unit tests.
[B] 2 — a full rewrite using HTMLPurifier, the exact library the maintainer requested.
[C] 3 — all 7 architectural changes the maintainer demanded, implemented and pushed. Every single test passing.
[D] None of the above. They were too busy trying to catch a ball at the Spain vs France World Cup 2026 final. Oh wait — France didn't play the final. They didn't even win the bronze match, losing 6-4 to England. Never mind then!

✅ CORRECT ANSWER: [D].

Three complete patches were submitted, reviewed, modified to the maintainer's exact specifications, and then rejected — after the maintainer himself admitted in writing: "I suggested HTMLPurifier, and you adapted to that and thanks again, but we're discussing that it may be a too big dependency."

Here is the vulnerability:

wallabag/wallabag versions >= 2.0.0 through <= 2.6.14 (current latest stable) store article title and content without sanitization. HTMLPurifier is completely absent from the codebase. The title field receives no filtering at all. Both fields are passed raw to TCPDF::writeHTMLCell() during PDF export. An authenticated attacker can trigger SSRF to cloud metadata endpoints (IMDSv1), internal network resources, and local file read via file:// protocol. The same fields are rendered unescaped with |raw in Twig templates (entry.html.twig, share.html.twig), enabling Stored XSS leading to session hijacking and Account Takeover.

Affected code paths:
— src/Controller/Api/EntryRestController.php ~line 965
— src/Helper/ContentProxy.php ~line 263
— src/Helper/EntriesExport.php lines 296–300

CWE-79 + CWE-918 + CWE-73 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N | 8.5 HIGH
GHSA-q2g2-www6-wf5h | CAN-2026-2035733

Unpatched. No CVE assigned. Advisory accepted June 28 then abandoned. Three fixes written, reviewed, and discarded. Version 2.6.14 released without any fix.

🎁 STEP 2 PRIZE: You win a weekend of your choice!

Option A: A weekend with me in Venice, all expenses paid. I mean it.
Option B: A weekend in Paris, on me, at the Wallabag community event — since they had time to organize that but not to merge a security patch.

🔴 STEP 3: THE GRAND FINALE

Final question for the ultimate prize:

What does it take to get a CVE assigned for a CVSS 8.5 vulnerability in a project whose maintainer accepted the report, requested three rounds of patches, got exactly what he asked for, reversed his own architectural direction, went silent, and then released a new version without any fix?

🎁 GRAND PRIZE: A full week in Italy with me, visiting any place you want — Rome, Florence, the Amalfi Coast, wherever you choose. All expenses on me. I'm serious.

The full advisory repository with complete timeline, proof of concept, and DKIM-verified email evidence is coming soon — and the winner of this quiz will be the first to know when it drops.

— Zampier Zago, Engineer
https://github.com/FUNFACTOR1

CW: Wallabag full disclosure — Stored XSS + SSRF CVSS 8.5 — GHSA-q2g2-www6-wf5h #infosec #vulnerability #disclosure #wallabag #xss #ssrf #cve

github.com
2
1
0
0
Open post
FUNFACTOR1 @FUNFACTOR1@infosec.exchange
· 1mo ago
Replying to
Another piece of puzzle.
0
0
0
0
Open post
FUNFACTOR1 @FUNFACTOR1@infosec.exchange
· 1mo ago

🎊 🎊 🎊 FOR ALL WINNER TO THE WALLABAG CHALLENGE🎊 🎊 🎊

I promised this:https://github.com/FUNFACTOR1/WALLABAG-FULL-DISCLOSURE-Stored-XSS-SSRF-CVSS-8.5-GHSA-q2g2-

github.com
0
0
0
0
Open post
FUNFACTOR1 @FUNFACTOR1@infosec.exchange
· 1mo ago

Hello everyone, remember that we have entered a period where daily or near-daily full disclosures are going to ramp up. We started from the bottom and we are heading toward something that affects roughly 3.2 billion people.

Are you ready for the next episode of """"NICK'S TIME MACHINE""""?

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:04:58 UTC