plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
GHSA-rr49-f9g6-c9r5 · CVE-2026-57149
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
The Classic portlet (plone.app.portlets.portlets.classic) used its user-supplied template/macro fields to build a TALES path expression that was then evaluated by the TAL path() helper. Because the value was interpreted as a full TALES expression, a user able to add or edit a Classic portlet could supply a crafted value that escapes simple path traversal and is evaluated as arbitrary code.
This is exploitable by any authenticated user who can configure a Classic portlet - which, with the default role map, includes regular users on their personal dashboard. The result is code execution in the context of the Plone process, i.e. a privilege escalation across the trust boundary between an authenticated web user and the server-side process.
Patches
The problem has been patched in plone.app.portlets
- For Plone 6.2, upgrade to
plone.app.portlets7.0.2. - For Plone 6.1, upgrade to
plone.app.portlets6.0.4. - For Plone 6.0, upgrade to
plone.app.portlets5.0.8.
Workarounds
If upgrading is not immediately possible:
- Restrict who can manage portlets: remove the
plone.app.portlets.ManageOwnPortletspermission from untrusted roles, and limit Manage portlets to trusted administrators (usually this is already restricted to the Manager and Site Administrator roles). - Where the Classic portlet is not needed, unregister it so it cannot be added. This would need to be done by editing a
portlets.xmlin your own code, so it is not a quick fix. - You could also effectively disable showing the classic portlet by customising its template. In the Zope Management Interface go to the
portal_view_customizationstool, locate theclassic.pttemplate and click it. Click the Customize button. Remove all text and replace it with<div>The classic portlet was disabled.</div>. (This is not a recommended way of customising a template, but in this case it is quite effective.)
Credits
Discovered by Giuseppe Caruso, and reported to the Plone/Zope Security Team. Thanks!
References
- WEB https://github.com/plone/plone.app.portlets/security/advisories/GHSA-rr49-f9g6-c9r5
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-57149
- WEB https://github.com/plone/plone.app.portlets/commit/1d9cacacfad9ed08b890dadc6e75741e295dc151
- WEB https://github.com/plone/plone.app.portlets/commit/8a0641dc4054a2b13834bba00c67cd9a2fd189e1
- WEB https://github.com/plone/plone.app.portlets/commit/fb979f01b57dd2fc06c90ee6577eb5eb285da8f1
- PACKAGE https://github.com/plone/plone.app.portlets
- WEB https://github.com/plone/plone.app.portlets/releases/tag/5.0.8
- WEB https://github.com/plone/plone.app.portlets/releases/tag/6.0.4
- WEB https://github.com/plone/plone.app.portlets/releases/tag/7.0.2
Ready to move
Start Securing
Free, no credit card | First findings in minutes