JSON Injection Vulnerability in PrivateBin Pastebin Application
CVE-2026-55891

NONE

Key Information:

Vendor

Privatebin

Vendor
CVE Published:
28 August 2026

What is CVE-2026-55891?

The vulnerability in PrivateBin affects its ability to sanitize URLs properly, allowing attackers to inject arbitrary key-value pairs into structured data responses. Prior to version 2.0.5, the handling of the REQUEST_URI does not adequately cleanse user inputs, leading to potential manipulation of JSON-LD templates. This issue could enable attackers to craft responses that affect clients consuming structured data, particularly in scenarios involving less strict content handling. Although direct execution of scripts was not demonstrated, the potential for information leakage or data manipulation poses significant risks to users. This vulnerability is mitigated in version 2.0.5, which addresses the input validation inadequacies.

Affected Version(s)

PrivateBin < 2.0.5

References

CVSS V3.1

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.