CVE-2026-18738 | shlinkio Shlink up to 5.1.5 CSV file User-Agent/Referer/request path csv injection

SecurityVulns

A vulnerability categorized as problematic has been discovered in shlinkio Shlink up to 5.1.5. This impacts an unknown function of the component CSV file Handler. The manipulation of the argument User-Agent/Referer/request path results in csv injection.

This vulnerability is known as CVE-2026-18738. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More