← Back to CVE List
CVE-2026-105263NVD
Vulnerability Summary
A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. Upgrading to version 0.16.4 is sufficient to fix this issue. The patch is named 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2. It is advisable to upgrade the affected component.
CVSS v4.0 Base Metrics — Score 5.1 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredHigh
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 4.7 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- n/a Shaarli >= 0.16.0
- n/a Shaarli >= 0.16.1
- n/a Shaarli >= 0.16.2
- n/a Shaarli >= 0.16.3
Not provided by cveorg for this CVE.
External References
- https://vuldb.com/vuln/413464
- https://vuldb.com/vuln/413464/cti
- https://vuldb.com/cve/CVE-2026-105263
- https://vuldb.com/submit/972906
- https://github.com/shaarli/Shaarli/security/advisories/GHSA-85jx-fhrf-q9w7
- https://github.com/shaarli/Shaarli/commit/8ca4de8e7c932a684481f5fbb1229fe16de1f4d2
- https://github.com/shaarli/Shaarli/releases/tag/v0.16.4
- https://github.com/shaarli/Shaarli/