Remote Code Execution Vulnerability in go-shiori Bookmark Management Tool
CVE-2026-71280
8.5HIGH
What is CVE-2026-71280?
The bookmark management tool go-shiori contains a vulnerability in its DownloadBookmark() function, allowing authenticated users to submit URLs that target internal services. This flaw arises from the tool's failure to validate the destination of HTTP requests properly, enabling the exploitation of loopback IP addresses. Consequently, an attacker could manipulate the server into making harmful outbound connections to internal resources, thereby exposing them to potential data breaches or other security risks.
Affected Version(s)
shiori 0
