Junglewise Threat Intelligence

CVE-2026-48822: Shaarli stored XSS in Markdown reference links

CVE-2026-48822 · Severity: medium · CVSS 5.8 · Published 2026-06-17

Technologies: Shaarli. Vendors: Shaarli.

Executive brief

Shaarli is a personal bookmarking service used to save and share web links. A security flaw allows an authorized user to create a bookmark with a malicious description that, when clicked by another user or administrator, executes unauthorized code in their browser. This could lead to account takeover, theft of sensitive session information, or unauthorized actions performed on behalf of the victim.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Shaarli versions 0.16.1 and prior due to insufficient sanitization in the BookmarkMarkdownFormatter.php component. The filterProtocols method uses a regular expression designed only to catch inline Markdown links, failing to account for reference-style Markdown links which are resolved after the initial preprocessing. An authenticated attacker with high privileges can inject a 'javascript:' URI into a reference-style link definition within a bookmark description. When a victim clicks the rendered link, the payload executes in the context of their session. This issue is resolved in version 0.16.2 by improving the sanitization of href protocols in rendered Markdown.

Affected products

  • Shaarli Shaarli <= 0.16.1

Timeline

  • 2026-05-23: patched: Version 0.16.2 released
  • 2026-05-23: advisory: GitHub Security Advisory GHSA-2hgr-63wv-x462 published
  • 2026-06-17: disclosed: CVE-2026-48822 published to NVD

References

Related threats