Server-Side Request Forgery in Shaarli by Shaarli Team
CVE-2026-105263

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105263?

A security vulnerability has been identified in Shaarli versions up to 0.16.3, specifically in the MetadataController function located in the Admin Metadata Endpoint. This flaw allows an attacker to manipulate the 'url' argument, potentially leading to server-side request forgery (SSRF) attacks that can be initiated remotely. It is crucial for users to upgrade to version 0.16.4, which contains the necessary patch identified by commit 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2, to mitigate this risk. Regular updates are essential to maintain security and protect against such vulnerabilities.

Affected Version(s)

Shaarli 0.16.0

Shaarli 0.16.1

Shaarli 0.16.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

akiner (VulDB User)
.