Impact
Shlink versions through 5.1.6 fail to enforce API key role restrictions when generating Mercure subscription tokens, allowing an attacker with a restricted author‑only or domain‑only key to subscribe to all Mercure topics. This flaw effectively bypasses authorization controls and lets the attacker access the mercure‑info endpoint, exposing visit data such as referrer, user agent, geolocation, and full short URL objects for URLs that fall outside the key’s authorized scope.
Affected Systems
The affected product is Shlink, developed by shlinkio, with all releases up to and including version 5.1.6 vulnerable. Any deployment using these releases is at risk.
Risk and Exploitability
The CVSS score of 7.1 ranks the issue as high severity, while the EPSS score of less than 1 % indicates a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, but attackers who already possess a restricted API key can exploit it by sending a request to the mercure‑info endpoint; no additional conditions or remote code execution are required. As a result, the primary risk is unauthorized disclosure of sensitive visit data and potential privilege escalation within the system.
OpenCVE Enrichment