Junglewise Threat Intelligence

CVE-2026-52100: andreimarcu linx-server CSRF in uploadPutHandler

CVE-2026-52100 · Severity: info · CVSS 7.5 · Published 2026-07-14

Technologies: Andrei Marcu Linx-Server. Vendors: Andrei Marcu.

Executive brief

linx-server is a self-hosted platform used for sharing files, code, and media. A security flaw in how the server handles file uploads allows unauthorized users to upload or modify content on the server. This could lead to the storage of malicious files or the replacement of legitimate data, potentially impacting the integrity of the hosted information.

Technical details

The vulnerability exists in the 'uploadPutHandler' function within 'upload.go'. While the application implements a 'strictReferrerCheck' for POST-based uploads to prevent cross-origin attacks, this check is missing for PUT-based uploads. An attacker can bypass intended origin restrictions to upload or modify files. Although modern browser CORS preflight (OPTIONS) requirements may mitigate direct cross-origin exploitation in some browser contexts, the lack of server-side validation allows direct API interaction and exploitation in environments with relaxed CORS policies or via non-browser clients.

Affected products

  • andreimarcu linx-server 1.0 - 2.3.8

Timeline

  • 2026-07-14: advisory: CVE published by NVD/MITRE

References

Related threats