CVE-2026-45344

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on uninitialized LinkAce instances accepts attacker-controlled database credential fields and writes them back into .env without escaping. A remote attacker who can reach the setup endpoints and supply a database they control can inject mail configuration variables and achieve command execution when the application later sends mail. This vulnerability is fixed in 2.5.6.
Configurations

No configuration.

History

01 Jun 2026, 21:16

Type Values Removed Values Added
References () https://github.com/Kovah/LinkAce/security/advisories/GHSA-37m5-936h-w455 - () https://github.com/Kovah/LinkAce/security/advisories/GHSA-37m5-936h-w455 -

28 May 2026, 22:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 22:17

Updated : 2026-06-01 21:16


NVD link : CVE-2026-45344

Mitre link : CVE-2026-45344

CVE.ORG link : CVE-2026-45344


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')