LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement proper authorization checks, allowing any authenticated user to access all links, lists, and tags from all users in the system, regardless of their ownership or visibility settings. This issue is fixed in version 2.4.0.
References
| Link | Resource |
|---|---|
| https://github.com/Kovah/LinkAce/commit/1fef32694cee2bd80892fb478416be9364c3fddd | Patch |
| https://github.com/Kovah/LinkAce/releases/tag/v2.4.0 | Release Notes |
| https://github.com/Kovah/LinkAce/security/advisories/GHSA-47g2-qw6q-cr96 | Exploit Vendor Advisory |
| https://github.com/Kovah/LinkAce/security/advisories/GHSA-47g2-qw6q-cr96 | Exploit Vendor Advisory |
Configurations
History
10 Nov 2025, 19:56
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| References | () https://github.com/Kovah/LinkAce/commit/1fef32694cee2bd80892fb478416be9364c3fddd - Patch | |
| References | () https://github.com/Kovah/LinkAce/releases/tag/v2.4.0 - Release Notes | |
| References | () https://github.com/Kovah/LinkAce/security/advisories/GHSA-47g2-qw6q-cr96 - Exploit, Vendor Advisory | |
| First Time |
Linkace linkace
Linkace |
|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:linkace:linkace:*:*:*:*:*:*:*:* |
05 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Kovah/LinkAce/security/advisories/GHSA-47g2-qw6q-cr96 - |
04 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-04 22:16
Updated : 2025-11-10 19:56
NVD link : CVE-2025-62721
Mitre link : CVE-2025-62721
CVE.ORG link : CVE-2025-62721
JSON object : View
Products Affected
linkace
- linkace
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-284Improper Access Control
NVD-CWE-noinfo