Junglewise Threat Intelligence

CVE-2026-85605: Slink authorization bypass in image comment endpoints

CVE-2026-85605 · Severity: medium · CVSS 5.3 · Published 2026-09-04

Executive brief

Slink is a self-hosted image sharing service that allows users to upload, organize, and share images with comment threads. The service fails to properly check user permissions on comment viewing endpoints, allowing anyone with a direct link or image ID to read all comments on public images and receive real-time comment updates without logging in. This exposes potentially sensitive discussions or metadata associated with images to unauthorized viewers.

Technical details

The vulnerability is an authorization bypass (improper access control) in Slink's REST API and server-sent-events (SSE) endpoints for image comments. Specifically, the GET /api/image/{imageId}/comments endpoint and SSE subscription mechanism fail to enforce authentication and authorization checks. An attacker who obtains an image ID (either from a public listing, direct link, or out-of-band sources) can retrieve the full comment thread and subscribe to live comment updates via the SSE stream without authentication. The vulnerability affects versions before 1.12.3, and was patched by enforcing voter access control on the SSE stream (commit 221315b1ac51). Attack vectors are network-based with no authentication required; an attacker only needs knowledge of a valid image ID.

Affected products

  • Andrii Kryvoviaz Slink before 1.12.3

Timeline

  • 2026-07-14: patched: Fix committed to main branch (commit 221315b1ac51) enforcing voter access control on SSE stream
  • 2026-09-04: disclosed

References