A Joomla plugin's GitHub auto-download skips TLS verification
The UP plugin for Joomla fetches action code from GitHub with certificate verification turned off, letting a network-positioned attacker swap in malicious PHP that Joomla then runs. Fixed in 5.2.1 and 6.1.0.
UP, a content plugin for Joomla from lomart.fr, disclosed a critical remote code execution bug on 26 September. It’s fixed in 5.2.1 and 6.1.0; versions 5.0.0 to 5.2.0 and 6.0.0 to 6.0.29 are affected.
CVE-2026-97163 (CVSS 10) sits in how the plugin’s mini package handles an action it hasn’t downloaded yet: it fetches the action’s code on demand from GitHub into plugins/content/up/actions/, and that fetch runs with TLS certificate verification disabled. An attacker in a position to intercept the connection, on a shared network, a compromised router, a hostile Wi-Fi hotspot, can substitute their own archive for GitHub’s. Joomla unpacks and executes whatever lands in that directory, no login or user interaction required beyond the plugin triggering its own download.
Why it matters: this isn’t a missing permission check, it’s an update mechanism that never checked who it was really talking to. If you run Joomla with this plugin, update now rather than waiting to see if it gets exploited, and it’s worth asking any other auto-updating plugin whether its own fetches verify TLS.
The caveat: exploitation needs an attacker who can intercept the plugin’s traffic to GitHub, not just anyone on the internet. There’s no report of active exploitation yet, but proof-of-concept code identifying vulnerable installs is already public.