PT-2025-27633 · Unknown · Linkwarden

Mrraul124

·

Published

2025-06-28

·

Updated

2025-07-02

·

CVE-2025-49588

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: Linkwarden version 2.10.2
Description: The issue concerns a File Path Disclosure Vulnerability in Linkwarden, a self-hosted, open-source collaborative bookmark manager. In the affected version, the server accepts links of the format file:///etc/passwd without validation, potentially leading to the leak of other users' links and, in some cases, environment secrets.
Recommendations: For version 2.10.2, update to version 2.10.3 to resolve the issue. As a temporary workaround, consider restricting the acceptance of links to validated formats to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05055
CVE-2025-49588
GHSA-RFC2-X8HR-536Q

Affected Products

Linkwarden