PT-2026-94042 · Git+1 · Shlink
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Shlink versions prior to 5.1.7
Description
Failure to enforce API key role restrictions occurs when issuing Mercure subscription tokens, which allows restricted keys to subscribe to all topics. This enables attackers possessing author-only or domain-only keys to access the 'mercure-info' endpoint and retrieve visit data, including referrer, user agent, geolocation, and full short URL objects for URLs that are outside their authorization boundary.
Recommendations
Update to version 5.1.7 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shlink