← voltar
CVE-2025-49588

Linkwarden Local File Inclusion Vulnerability

CVSS 8.7 HIGHEPSS 0.3%CWE-73
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.7EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
02 jul 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version 2.10.2, the server accepts links of format file:///etc/passwd and doesn't do any validation before sending them to parsers and playwright, this can result in leak of other user's links (and in some cases it might be possible to leak environment secrets). This issue has been patched in version 2.10.3 which has not been made public at time of publication.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
linkwarden · linkwarden

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →