CyberRota Analysis
AI-GeneratedThe Bulk Link API endpoint in LinkAce prior to version 2.5.7 is vulnerable to a lack of URL format validation, allowing authenticated users to store malicious `javascript:` URIs. This vulnerability can lead to the execution of arbitrary JavaScript in victims' browsers, potentially exfiltrating sensitive information such as cookies and session tokens. Organizations using affected versions of LinkAce should prioritize updating to version 2.5.7 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered verbatim as an `href` in Blade templates, and clicking it executes arbitrary JavaScript in the victim's browser — exfiltrating cookies and session tokens. Version 2.5.7 fixes the issue.