CVE-2026-105263 | Shaarli up to 0.16.3 Admin Metadata Endpoint MetadataController.php MetadataController url server-side request forgery (GHSA-85jx-fhrf-q9w7)
A vulnerability, which was classified as problematic, has been found in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component Admin Metadata Endpoint. Performing a manipulation of the argument url results in server-side request forgery.
This vulnerability was named CVE-2026-105263. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More