Description
A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. Upgrading to version 0.16.4 is sufficient to fix this issue. The patch is named 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2. It is advisable to upgrade the affected component.
Published: 2026-10-05
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch
AI Analysis

Impact

The vulnerability occurs in a function that handles a URL parameter within the Admin Metadata Endpoint of Shaarli. Manipulating this URL argument allows an attacker to make the server fetch arbitrary resources, enabling a server‑side request forgery (SSRF). The flaw does not lead to arbitrary code execution or direct data exfiltration, but it can be leveraged to probe internal systems, access privileged resources, or carry out further attacks. This injected request capability can be used by a remote actor to execute queries against internal networks or external services.

Affected Systems

Shaarli, the open‑source link shortener, is affected in all releases up to and including version 0.16.3. The fix was introduced in release 0.16.4, so any deployment running a vulnerable version of Shaarli must be updated to 0.16.4 or newer.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The description states that an attacker may manipulate the URL argument to make the server fetch arbitrary resources, allowing server‑side request forgery. Based on this description, it is inferred that the flaw can be triggered remotely without authentication, implying a low barrier to exploitation. An attacker could craft a malicious request to the Metadata endpoint and supply a URL that the server will request, potentially allowing third‑party content retrieval or internal network probing. It is further inferred that if the server processes responses or follows redirects, this could be abused to discover internal hosts.

Generated by OpenCVE AI on October 5, 2026 at 11:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Shaarli to version 0.16.4 or later using the commit 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2.
  • Configure the application or hosting environment to restrict outbound HTTP/HTTPS calls to trusted domains, or implement a whitelist of allowed IP ranges, to limit the impact of potential SSRF requests.
  • Deploy monitoring or an intrusion detection mechanism that alerts on unexpected outbound requests originating from the application, and review logs for suspicious activity.

Generated by OpenCVE AI on October 5, 2026 at 11:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. Upgrading to version 0.16.4 is sufficient to fix this issue. The patch is named 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2. It is advisable to upgrade the affected component.
Title Shaarli Admin Metadata Endpoint MetadataController.php MetadataController server-side request forgery
First Time appeared Shaarli
Shaarli shaarli
Weaknesses CWE-918
CPEs cpe:2.3:a:shaarli:shaarli:*:*:*:*:*:*:*:*
Vendors & Products Shaarli
Shaarli shaarli
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T13:22:01.694Z

Reserved: 2026-10-04T21:54:30.390Z

Link: CVE-2026-105263

cve-icon Vulnrichment

Updated: 2026-10-05T13:21:56.672Z

cve-icon NVD

Status : Deferred

Published: 2026-10-05T09:17:12.130

Modified: 2026-10-05T14:17:20.110

Link: CVE-2026-105263

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)