CVE-2026-105263: Shaarli Admin Metadata Endpoint MetadataController.php MetadataController server-side request forgery
A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. Upgrading to version 0.16.4 is sufficient to fix this issue. The patch is named 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2. It is advisable to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Shaarlito a version that resolves this vulnerability.Fixed in 0.16.4Patch 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2
Event History
Frequently Asked Questions
Which deployments are affected?
Shaarli versions up to and including 0.16.3 are affected. Version 0.16.4 fixes the issue.
What access does an attacker need to exploit this?
The vulnerable functionality is an Admin Metadata Endpoint, and the supplied vector lists privileges required as high. Exploitation can be initiated remotely by manipulating the url argument.
What is the recommended remediation?
Upgrade Shaarli to version 0.16.4. The fix is identified by patch 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2.