Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 12 May 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linkwarden
Linkwarden linkwarden |
|
| Vendors & Products |
Linkwarden
Linkwarden linkwarden |
Fri, 08 May 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In versions 2.14.0 and prior, the archive upload endpoint (POST /api/v1/archives/[linkId]?format=4) accepts HTML files (text/html) without sanitizing JavaScript content. When the archive is later accessed via GET /api/v1/archives/[linkId]?format=4, the HTML is served with Content-Type: text/html from the Linkwarden origin, without any Content-Security-Policy header. This allows arbitrary JavaScript execution in the context of the authenticated Linkwarden sessio. At time of publication, there are no publicly available patches. | |
| Title | LinkWarden: Stored XSS via Client-Side Archive Upload (Unsanitized HTML served from same origin) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-12T02:19:23.519Z
Reserved: 2026-04-27T13:55:58.693Z
Link: CVE-2026-42455
Updated: 2026-05-12T02:19:05.999Z
Status : Deferred
Published: 2026-05-09T00:16:29.180
Modified: 2026-05-12T16:39:33.760
Link: CVE-2026-42455
No data.
OpenCVE Enrichment
Updated: 2026-05-10T21:24:38Z