CVE-2025-49588
Awaiting Analysis Awaiting Analysis - Queue
BaseFortify

Publication date: 2025-07-02

Last updated on: 2025-07-03

Assigner: GitHub, Inc.

Description
Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version 2.10.2, the server accepts links of format file:///etc/passwd and doesn't do any validation before sending them to parsers and playwright, this can result in leak of other user's links (and in some cases it might be possible to leak environment secrets). This issue has been patched in version 2.10.3 which has not been made public at time of publication.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-02
Last Modified
2025-07-03
Generated
2026-05-07
AI Q&A
2025-07-02
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The vulnerability in Linkwarden version 2.10.2 involves the server accepting links with the format file:///etc/passwd without validating them before processing with parsers and playwright. This lack of validation can lead to leaking other users' links and, in some cases, environment secrets. The issue was fixed in version 2.10.3.


How can this vulnerability impact me? :

This vulnerability can lead to unauthorized disclosure of other users' bookmarked links and potentially sensitive environment secrets, which could compromise user privacy and system security.


What immediate steps should I take to mitigate this vulnerability?

Upgrade Linkwarden to version 2.10.3 or later once it is publicly available, as this version contains the patch for the vulnerability. Until then, restrict access to the Linkwarden server to trusted users only and avoid processing untrusted links with the file:/// format to prevent potential information leaks.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart