CVE 7.1 HIGH

LinkAce: Authorization Bypass Allows Unauthorized Access to All Private Links, Lists, and Tags_CVE-2025-62721

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement proper authorization checks, allowing any authenticated user to access all links, lists, and tags from all users in the system, regardless of their ownership or visibility settings. This issue is fixed in version 2.4.0.

Basic Information

ID CVE-2025-62721
Source GitHub_M
Published Nov 4, 2025 at 22:07

Affected Product

Vendor Kovah
Product LinkAce
Version < 2.4.0
Affected Versions Kovah LinkAce < 2.4.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.