Hi,
The following vulnerability was published for shaarli.
CVE-2026-105263[0]:
| A security flaw has been discovered in Shaarli up to 0.16.3. The
| affected element is the function MetadataController of the file
| application/front/controller/admin/MetadataController.php of the
| component Admin Metadata Endpoint. Performing a manipulation of the
| argument url results in server-side request forgery. The attack may
| be initiated remotely. Upgrading to version 0.16.4 is sufficient to
| fix this issue. The patch is named
| 8ca4de8e7c932a684481f5fbb1229fe16de1f4d2. It is advisable to upgrade
| the affected component.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-105263
https://www.cve.org/CVERecord?id=CVE-2026-105263
[1] https://github.com/shaarli/Shaarli/security/advisories/GHSA-85jx-fhrf-q9w7
[2] https://github.com/shaarli/Shaarli/commit/8ca4de8e7c932a684481f5fbb1229fe16de1f4d2
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore