Executive brief
alf.io is an open-source ticket reservation system used for managing events like conferences and workshops. A security flaw in the system's extension engine allows an administrator to bypass security restrictions and execute unauthorized commands on the underlying server. This could lead to a complete takeover of the server, resulting in the theft of attendee data, service outages, or the use of the server for further attacks.
Technical details
A sandbox escape exists in the alf.io extension script engine due to the improper exposure of Java objects within the Rhino JavaScript environment. Specifically, the `ScriptingExecutionService.executeScriptFinally()` method injects an unrestricted `java.lang.Class` object (named `returnClass`) into the script scope. While the system attempts to use AST validation and a class whitelist to restrict script capabilities, an attacker can use `returnClass.forName()` and Java reflection to bypass these controls. By reflecting into `java.lang.Runtime`, an authenticated administrator can execute arbitrary OS commands. The vulnerability is triggered when a malicious extension script is saved and subsequently executed by a system event. This issue is patched in version 2.0-M5-2606.
Affected products
- alfio-event alf.io < 2.0-M5-2606
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory
- 2026-06-02: patched