Remote Code Execution Vulnerability in go-shiori Bookmark Management Tool
CVE-2026-71280

8.5HIGH

Key Information:

Vendor

Go-shiori

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71280?

The bookmark management tool go-shiori contains a vulnerability in its DownloadBookmark() function, allowing authenticated users to submit URLs that target internal services. This flaw arises from the tool's failure to validate the destination of HTTP requests properly, enabling the exploitation of loopback IP addresses. Consequently, an attacker could manipulate the server into making harmful outbound connections to internal resources, thereby exposing them to potential data breaches or other security risks.

Affected Version(s)

shiori 0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alibek Baxtiyorov
.