CVE-2026-27458
Last modified
CVE-2026-27458 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting vulnerability through the Atom feed endpoint for lists (/lists/feed). EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting vulnerability through the Atom feed endpoint for lists (/lists/feed). An authenticated user can inject a CDATA-breaking payload into a list description that escapes the XML CDATA section, injects a native SVG element into the Atom XML document, and executes arbitrary JavaScript directly in the browser when the feed URL is visited. No RSS reader or additional rendering context is required — the browser's native XML parser processes the injected SVG and fires the onload event handler. This vulnerability exists because the lists feed template outputs list descriptions using Blade's raw syntax ({!! !!}) without sanitization inside a CDATA block. The critical detail is that because the output sits inside <![CDATA[...]]>, an attacker can inject the sequence ]]> to close the CDATA section prematurely, then inject arbitrary XML/SVG elements that the browser parses and executes natively as part of the Atom document. This issue has been fixed in version 2.4.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linkace | Linkace | < 2.4.3 |
References
- https://github.com/Kovah/LinkAce/security/advisories/GHSA-2r9p-95xj-p583Exploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27458?
How severe is CVE-2026-27458?
How do I fix CVE-2026-27458?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-27449Umbraco Engage is a business intelligence platform. A vulner…7.5
- CVE-2026-2745GitLab has remediated an issue in GitLab CE/EE affecting all…8.1
- CVE-2026-27452ASN.1 TypeScript ESM library, including codecs for Basic Enc…5.3
- CVE-2026-27454Discourse is an open-source discussion platform. Prior to ve…5.3
- CVE-2026-27456util-linux is a random collection of Linux utilities. Prior …4.7
- CVE-2026-27457Weblate is a web based localization tool. Prior to version 5…4.3
- CVE-2026-27459pyOpenSSL is a Python wrapper around the OpenSSL library. St…9.8
- CVE-2026-2746SEPPmail Secure Email Gateway before version 15.0.1 does not…5.3
- CVE-2026-27460Tandoor Recipes is an application for managing recipes, plan…6.5
- CVE-2026-27461Pimcore is an Open Source Data & Experience Management Platf…4.9
- CVE-2026-27464Metabase is an open-source data analytics platform. In versi…6.5
- CVE-2026-27465Fleet is open source device management software. In versions…6.5
Are you affected by CVE-2026-27458?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
