Vulnerability Description
LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered verbatim as an `href` in Blade templates, and clicking it executes arbitrary JavaScript in the victim's browser — exfiltrating cookies and session tokens. Version 2.5.7 fixes the issue.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Kovah/LinkAce/commit/642ac520347205a8277668bcae269bdc21223eae
- https://github.com/Kovah/LinkAce/security/advisories/GHSA-6r73-pchm-4m39
- https://github.com/Kovah/LinkAce/security/advisories/GHSA-6r73-pchm-4m39
FAQ
What is CVE-2026-49436?
CVE-2026-49436 is a vulnerability with a CVSS score of 7.3 (HIGH). LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authen...
How severe is CVE-2026-49436?
CVE-2026-49436 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-49436?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.