Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-49436

HIGH NVD
CVSS Score 7.3
Severity HIGH
Published Aug 20, 2026
Vendor unknown

Description

LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered verbatim as an `href` in Blade templates, and clicking it executes arbitrary JavaScript in the victim's browser โ€” exfiltrating cookies and session tokens. Version 2.5.7 fixes the issue.

References