[pkg-php-pear] Bug#1150167: shaarli: CVE-2026-105263
Salvatore Bonaccorso
carnil at debian.org
Tue Oct 6 12:56:35 BST 2026
Package: shaarli
Version: 0.16.1+dfsg-1
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: security upstream
Hi,
The following vulnerability was published for shaarli.
CVE-2026-105263[0]:
| A security flaw has been discovered in Shaarli up to 0.16.3. The
| affected element is the function MetadataController of the file
| application/front/controller/admin/MetadataController.php of the
| component Admin Metadata Endpoint. Performing a manipulation of the
| argument url results in server-side request forgery. The attack may
| be initiated remotely. Upgrading to version 0.16.4 is sufficient to
| fix this issue. The patch is named
| 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2. It is advisable to upgrade
| the affected component.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-105263
https://www.cve.org/CVERecord?id=CVE-2026-105263
[1] https://github.com/shaarli/Shaarli/security/advisories/GHSA-85jx-fhrf-q9w7
[2] https://github.com/shaarli/Shaarli/commit/8ca4de8e7c932a684481f5fbb1229fe16de1f4d2
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
More information about the pkg-php-pear
mailing list