JSON Injection Vulnerability in PrivateBin Pastebin Application
CVE-2026-55891
What is CVE-2026-55891?
The vulnerability in PrivateBin affects its ability to sanitize URLs properly, allowing attackers to inject arbitrary key-value pairs into structured data responses. Prior to version 2.0.5, the handling of the REQUEST_URI does not adequately cleanse user inputs, leading to potential manipulation of JSON-LD templates. This issue could enable attackers to craft responses that affect clients consuming structured data, particularly in scenarios involving less strict content handling. Although direct execution of scripts was not demonstrated, the potential for information leakage or data manipulation poses significant risks to users. This vulnerability is mitigated in version 2.0.5, which addresses the input validation inadequacies.
Affected Version(s)
PrivateBin < 2.0.5
