Executive brief
LibreBooking, an open-source reservation and booking system, contains a security flaw in its email template editor. An authorized administrator can bypass folder restrictions to save malicious files onto the server. This could allow an attacker with administrative access to take full control of the underlying web server and execute arbitrary code.
Technical details
A relative path traversal vulnerability (CWE-23) exists in LibreBooking's ManageEmailTemplatesPresenter.php. The 'save' action for email templates fails to validate the template name, allowing it to be used directly in a file path construction. An attacker with administrative privileges can provide a crafted template name containing traversal sequences (e.g., '../') to write files to arbitrary locations on the server, such as the web root. This can be leveraged to upload a PHP shell and achieve remote code execution (RCE). The issue was addressed by centralizing template name validation in a shared helper that enforces allowed extensions and rejects directory separators.
Affected products
- LibreBooking LibreBooking < 5.1.0
Timeline
- 2026-06-07: patched: Fixed in version 5.1.0 via pull request #1456
- 2026-07-09: disclosed: CVE-2026-61343 published
References
- https://github.com/LibreBooking/librebooking/commit/cb9b7ad9da0243bd105809f6a4a8a6b9147c71ea
- https://github.com/LibreBooking/librebooking/pull/1456
- https://github.com/LibreBooking/librebooking/releases/tag/v5.1.0
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-190-01.json
- https://www.cve.org/CVERecord?id=CVE-2026-61343