CVE-2026-49436
HIGH
NVD
CVSS Score
7.3
Severity
HIGH
Published
Aug 20, 2026
Vendor
unknown
Description
LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered verbatim as an `href` in Blade templates, and clicking it executes arbitrary JavaScript in the victim's browser โ exfiltrating cookies and session tokens. Version 2.5.7 fixes the issue.