---
id: CVE-2026-77353
title: 'Wallos is an open-source, self-hostable personal subscription tracker'
summary: >-
  Wallos is an open-source, self-hostable personal subscription tracker. Prior
  to version 5.0.0, Wallos allows authenticated users to inject arbitrary
  iCalendar properties and events into their exported .ics feed by embedding raw
  CRLF sequ…
severity: medium
cvss: 4.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-74
  - CWE-116
published: '2026-08-31'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T21:11:31.703'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77353'
references:
  - url: >-
      https://github.com/ellite/Wallos/commit/11eaf402e841a628c68a805694227ce66c45f6f3
    label: security-advisories@github.com
  - url: 'https://github.com/ellite/Wallos/releases/tag/v5.0.0'
    label: security-advisories@github.com
  - url: 'https://github.com/ellite/Wallos/security/advisories/GHSA-q2r8-m9wm-5547'
    label: security-advisories@github.com
  - url: 'https://github.com/ellite/Wallos/security/advisories/GHSA-q2r8-m9wm-5547'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00289
epssPercentile: 0.19129
ingestedAt: '2026-09-08T22:12:30.945Z'
---

## Overview

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by embedding raw CRLF sequences in subscription names or notes. Because the input validation layer only encodes HTML metacharacters but never strips newlines, and the export layer decodes those entities back before writing iCal output, an attacker with any valid account can craft a subscription whose name breaks out of the current VEVENT block and inserts fully attacker-controlled calendar events — including spoofed organizers, arbitrary email addresses in ATTENDEE properties, and misleading event content — into any calendar application subscribed to that feed. This issue has been patched in version 5.0.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
