Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version 2.10.2, the server accepts links of format file:///etc/passwd and doesn't do any validation before sending them to parsers and playwright, this can result in leak of other user's links (and in some cases it might be possible to leak environment secrets). This issue has been patched in version 2.10.3 which has not been made public at time of publication.
History

Wed, 02 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Description Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version 2.10.2, the server accepts links of format file:///etc/passwd and doesn't do any validation before sending them to parsers and playwright, this can result in leak of other user's links (and in some cases it might be possible to leak environment secrets). This issue has been patched in version 2.10.3 which has not been made public at time of publication.
Title Linkwarden Local File Inclusion Vulnerability
Weaknesses CWE-73
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-02T14:05:29.039Z

Updated: 2025-07-02T14:23:32.937Z

Reserved: 2025-06-06T15:44:21.556Z

Link: CVE-2025-49588

cve-icon Vulnrichment

Updated: 2025-07-02T14:23:28.339Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-02T14:15:25.590

Modified: 2025-07-03T15:13:53.147

Link: CVE-2025-49588

cve-icon Redhat

No data.