Sceawere
Vulnerability Detail
CVE-2026-105263UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Shaarli Server-Side Request Forgery
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 10h ago
- Vendor
- n/a
- Product
- Shaarli
- Attack Type
- Server-Side Request Forgery
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. Upgrading to version 0.16.4 is sufficient to fix this issue. The patch is named 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2. It is advisable to upgrade the affected component.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-10-05T09:17:12.130Z",
"pubdate": "2026-10-05T09:17:12.130Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in Shaarli versions up to 0.16.3.\nThe flaw resides within the MetadataController component, specifically impacting the handling of user-supplied URL arguments.\nThis vulnerability allows an unauthenticated or remote attacker to force the application to perform unauthorized requests to arbitrary internal or external resources.\nSuccessful exploitation can lead to unauthorized information disclosure, interaction with internal services protected by firewalls, and potential service disruption.\nThe risk is critical due to the potential for bypassing network segmentation and accessing restricted administrative or metadata endpoints within the internal network infrastructure.\nRemediation requires updating the Shaarli installation to version 0.16.4, which incorporates the necessary security patches to validate and restrict request targets.",
"technicalDetails": "The vulnerability is located in application/front/controller/admin/MetadataController.php, specifically within the MetadataController function.\nThe root cause of this SSRF vulnerability is the improper validation and sanitization of the 'url' argument passed to the MetadataController.\nThe application accepts a user-provided URL and processes it as an input for fetching metadata, without implementing adequate access control or URI schema validation.\nAn attacker can exploit this by crafting a malicious request where the 'url' parameter points to internal infrastructure IP addresses (e.g., 127.0.0.1, 192.168.x.x) or sensitive local services that are not normally reachable from the public internet.\nThe attack flow proceeds as follows: 1) The attacker identifies the vulnerable MetadataController endpoint. 2) The attacker submits an HTTP request to the controller, supplying a malicious URL in the 'url' argument. 3) The server-side code executes the request initiated by the MetadataController function to the target URL provided by the attacker. 4) The application processes the response from the target server, potentially leaking data contained in the response or confirming the existence of internal services based on application behavior.\nBecause the request originates from the server running the Shaarli application, it can bypass perimeter security controls such as firewalls, enabling the attacker to interact with services that trust the server's local network location.\nThe impact includes the ability to perform port scanning of the internal network, interact with internal APIs, or bypass authentication mechanisms that rely on IP-based trust models.\nThis vulnerability affects Shaarli versions 0.16.3 and prior. The patch identified by commit 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2 addresses the flaw by implementing stricter validation logic to prevent unauthorized resource access via the MetadataController."
}