CVE-2026-33953
Published
CVSS v3
8.5
HIGH
CVSS v2
N/A
Affected
1
PROJECT
Description
LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resources when those resources are referenced through an internal hostname. This allows an authenticated user to trigger server-side requests to internal services reachable by the LinkAce server but not directly reachable by an external user. Version 2.5.3 patches the issue.
LinkAce is a self-hosted archive to collect links of your favorite websites.