PT-2025-45056 · Linkace · Linkace

Published

2025-11-04

·

Updated

2025-11-10

·

CVE-2025-62721

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LinkAce versions 2.3.1 and below
Description LinkAce is a self-hosted archive to collect website links. Authenticated RSS feed endpoints in the FeedController class do not implement proper authorization checks. This allows any authenticated user to access all links, lists, and tags from all users in the system, regardless of their ownership or visibility settings.
Recommendations Update to version 2.4.0 or later.

Exploit

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-62721
GHSA-47G2-QW6Q-CR96

Affected Products

Linkace