Impact
Shlink contains a server‑side request forgery vulnerability that allows holders of an authenticated API key to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto‑resolution enabled. The attacker can target external hosts that redirect to internal or loopback addresses, link‑local ranges, or cloud metadata endpoints such as 169.254.169.254, and exfiltrate internal service information via the HTML title element returned in the short URL creation response.
Affected Systems
The affected system is the Shlink platform supplied by shlinkio. No specific version information is provided in the advisory, so all versions hosted by shlinkio may be impacted until a patch is released.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be through authenticated API usage; an attacker with an API key can submit a malicious URL that forces the server to contact internal resources, potentially exposing confidential data. The lack of available EPSS data means the exploitation probability is unknown, but the presence of an authentication requirement mitigates the immediate risk to unauthenticated users.
OpenCVE Enrichment