PT-2025-27633 · Unknown · Linkwarden
Mrraul124
·
Published
2025-06-28
·
Updated
2025-07-02
·
CVE-2025-49588
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions:
Linkwarden version 2.10.2
Description:
The issue concerns a File Path Disclosure Vulnerability in Linkwarden, a self-hosted, open-source collaborative bookmark manager. In the affected version, the server accepts links of the format
file:///etc/passwd without validation, potentially leading to the leak of other users' links and, in some cases, environment secrets.Recommendations:
For version 2.10.2, update to version 2.10.3 to resolve the issue. As a temporary workaround, consider restricting the acceptance of links to validated formats to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linkwarden