CVE-2026-49436
7.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Summary
LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (POST /api/v2/bulk/links) accepts URLs without any format validation, allowing an authenticated user to store a javascript: URI. The stored URI is later rendered verbatim as an href in Blade templates, and clicking it executes arbitrary JavaScript in the victim's browser — exfiltrating cookies and session tokens. Version 2.5.7 fixes the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Kovah | LinkAce | < 2.5.7 | affected |
Weaknesses
- CWE-79: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
References
- https://github.com/Kovah/LinkAce/security/advisories/GHSA-6r73-pchm-4m39
- https://github.com/Kovah/LinkAce/commit/642ac520347205a8277668bcae269bdc21223eae
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.