Vulnerability Description
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on uninitialized LinkAce instances accepts attacker-controlled database credential fields and writes them back into .env without escaping. A remote attacker who can reach the setup endpoints and supply a database they control can inject mail configuration variables and achieve command execution when the application later sends mail. This vulnerability is fixed in 2.5.6.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Kovah/LinkAce/security/advisories/GHSA-37m5-936h-w455
- https://github.com/Kovah/LinkAce/security/advisories/GHSA-37m5-936h-w455
FAQ
What is CVE-2026-45344?
CVE-2026-45344 is a vulnerability with a CVSS score of 8.1 (HIGH). LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on uninitialized LinkAce instances accepts attacker-controlled database credential fiel...
How severe is CVE-2026-45344?
CVE-2026-45344 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45344?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.