PT-2026-85538 · S Link · Slink
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Slink versions prior to 1.12.3
Description
Improper authorization in image comment endpoints allows unauthenticated attackers to read comment threads. By obtaining image IDs out of band, an attacker can retrieve full comment threads on public images and subscribe to live comment updates. This is possible via the endpoint 'GET /api/image/{imageId}/comments' and server-sent-events subscriptions, which lack necessary authentication or authorization checks.
Recommendations
Update to version 1.12.3 or later.
Restrict access to the 'GET /api/image/{imageId}/comments' endpoint as a temporary mitigation.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Slink