Description
YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the value in yourls-infos.php and passes the derived domain through yourls_get_domain(), yourls_stats_pie(), and yourls_google_array_to_data_table(). The chart builder concatenates labels into inline JavaScript without JavaScript-string escaping, so an unauthenticated attacker can poison the statistics of an existing short URL with a crafted referrer. When an administrator or public stats-page viewer opens the affected statistics page, attacker-controlled JavaScript executes in the YOURLS origin and can access admin-visible data, the API signature token, and privileged same-origin actions. This issue is fixed in version 1.10.4.
Published: 2026-08-21
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

YOURLS version 1.5.1 through 1.10.4 stores the HTTP Referer header without proper escaping, allowing a crafted Referer to be embedded directly into an inline JavaScript chart on the statistics page. The resulting stored XSS enables any user who views that page—including administrators—to execute arbitrary scripts within the YOURLS origin. Attackers can read admin‑visible data, the API signature token, and perform privileged same‑origin actions, effectively compromising the entire site.

Affected Systems

The vulnerability applies to all installations of YOURLS between release 1.5.1 and 1.10.4. Users of YOURLS older than 1.5.1 or newer than 1.10.4 are not affected, unless they manually re‑enable referrer logging with the same code path. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. The EPSS score is not available, and the vulnerability is not present in the CISA KEV catalog, suggesting no publicly known exploits at the time of this analysis. The attack vector is likely a web request with a crafted Referer header, which can be sent from any device without authentication. An attacker only needs to trigger a redirect to a short URL to poison the statistics chart. Once the statistics page is rendered by an administrator or any authenticated user, the injected JavaScript runs with full site privileges. Because the flaw is stored, the impact spans all future views of the affected statistics page.

Generated by OpenCVE AI on August 21, 2026 at 21:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade YOURLS to version 1.10.4 or later.
  • Disable or sanitize the Referer header before storing it if the feature is required.
  • Configure the statistics page to require authentication or restrict it to trusted users only.

Generated by OpenCVE AI on August 21, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5h77-88j3-r659 YOURLS has stored XSS in referrer statistics chart via crafted Referer header
History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Yourls
Yourls yourls
Vendors & Products Yourls
Yourls yourls

Fri, 21 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the value in yourls-infos.php and passes the derived domain through yourls_get_domain(), yourls_stats_pie(), and yourls_google_array_to_data_table(). The chart builder concatenates labels into inline JavaScript without JavaScript-string escaping, so an unauthenticated attacker can poison the statistics of an existing short URL with a crafted referrer. When an administrator or public stats-page viewer opens the affected statistics page, attacker-controlled JavaScript executes in the YOURLS origin and can access admin-visible data, the API signature token, and privileged same-origin actions. This issue is fixed in version 1.10.4.
Title YOURLS: Stored XSS in referrer statistics chart via crafted Referer header
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T20:40:08.199Z

Reserved: 2026-07-15T16:54:55.817Z

Link: CVE-2026-63135

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-21T21:17:01.493

Modified: 2026-08-21T21:17:01.493

Link: CVE-2026-63135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')