Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version 2.10.2, the server accepts links of format file:///etc/passwd and doesn't do any validation before sending them to parsers and playwright, this can result in leak of other user's links (and in some cases it might be possible to leak environment secrets). This issue has been patched in version 2.10.3 which has not been made public at time of publication.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 02 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version 2.10.2, the server accepts links of format file:///etc/passwd and doesn't do any validation before sending them to parsers and playwright, this can result in leak of other user's links (and in some cases it might be possible to leak environment secrets). This issue has been patched in version 2.10.3 which has not been made public at time of publication. | |
Title | Linkwarden Local File Inclusion Vulnerability | |
Weaknesses | CWE-73 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-02T14:05:29.039Z
Updated: 2025-07-02T14:23:32.937Z
Reserved: 2025-06-06T15:44:21.556Z
Link: CVE-2025-49588

Updated: 2025-07-02T14:23:28.339Z

Status : Awaiting Analysis
Published: 2025-07-02T14:15:25.590
Modified: 2025-07-03T15:13:53.147
Link: CVE-2025-49588

No data.