Server-Side Request Forgery in Shaarli by Shaarli Team
CVE-2026-105263
5.1MEDIUM
What is CVE-2026-105263?
A security vulnerability has been identified in Shaarli versions up to 0.16.3, specifically in the MetadataController function located in the Admin Metadata Endpoint. This flaw allows an attacker to manipulate the 'url' argument, potentially leading to server-side request forgery (SSRF) attacks that can be initiated remotely. It is crucial for users to upgrade to version 0.16.4, which contains the necessary patch identified by commit 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2, to mitigate this risk. Regular updates are essential to maintain security and protect against such vulnerabilities.
Affected Version(s)
Shaarli 0.16.0
Shaarli 0.16.1
Shaarli 0.16.2
