CVE-2026-45343 Details
Description
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a low-privilege user to execute arbitrary JavaScript in an administrator's browser session. This affects instances configured with SSO/OAuth authentication, which is one of the supported authentication methods in LinkAce. An attacker who sets their OAuth display name to a malicious script and then creates an API token will plant a persistent XSS payload in the audit log. When any admin navigates to /system/audit, the payload executes in the admin's browser context. This enables session cookie theft, CSRF token exfiltration (exposed in the la-app-data meta tag), or any other action the admin can perform. This vulnerability is fixed in 2.5.6.
A stored cross-site scripting vulnerability has been identified in LinkAce versions prior to 2.5.6. This issue allows low-privilege users to execute arbitrary JavaScript in the context of an administrator's browser session. The vulnerability affects instances using SSO/OAuth authentication. When a user authenticates via SSO, the OAuth provider's display name is stored without proper sanitization. An attacker can exploit this by injecting a malicious script into their display name, which is then executed when an admin views the audit log. This could lead to session cookie theft, CSRF token exfiltration, or unauthorized actions performed as the admin.
Users can update to LinkAce version 2.5.6, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 28, 2026CISA-ADP
Assessed May 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Kovah/LinkAce/security/advisories/GHSA-jx4g-ph82-x9mm | CISA-ADP | AdvisoryExploitRemedyTechnical AnalysisVendor |
| https://github.com/Kovah/LinkAce/security/advisories/GHSA-jx4g-ph82-x9mm | [email protected] | AdvisoryExploitRemedyTechnical AnalysisVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| LinkAce | <= 2.5.5 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 30, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | New CVE Received | [email protected] |
Volerion