CVE-2026-61343 is a path traversal vulnerability in LibreBooking affecting versions prior to 5.1.0. The flaw is in the email template editor save action, which incorporates a submitted template name directly into the destination file path without properly restricting it to the intended template directory. An authenticated remote attacker with administrator credentials can exploit this behavior to write arbitrary files outside the template directory. Because the attacker can place controlled content in writable locations used by the application, successful exploitation can lead to arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, single-purpose exploit PoC for CVE-2026-61343 affecting LibreBooking. It contains one Python script (librebooking_rce.py), a minimal README, and a license file. The Python script is the sole functional component and serves as the entry point. The exploit workflow is straightforward: it logs into LibreBooking using supplied administrator credentials, requests the admin email template management page, parses a CSRF token from an HTML input named CSRF_TOKEN, and then submits an update request to /Web/admin/manage_email_templates.php?action=update. The core vulnerability is a path traversal in the EMAIL_TEMPLATE_NAME parameter, which the script sets to ../../Web/<shell_name> so that attacker-controlled content is written outside the intended language template directory and into the web-accessible /Web/ directory. The payload written is a basic PHP webshell: it reads the cmd GET parameter and passes it to shell_exec(), returning command output in the HTTP response. After writing the file, the script immediately accesses /Web/<shell_name>?cmd=<command> to verify code execution and print the result. Default behavior writes lb_shell.php and runs the id command. Capabilities: authenticated admin login, CSRF token extraction, arbitrary file write via path traversal, placement of a PHP webshell in the web root, and remote command execution through that webshell. This is an actual exploit rather than a detector. It is operational but basic: the payload is hardcoded and limited to a simple command-execution webshell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.