CVE-2026-45344

HIGH CVSS 3.1: 8.1 EPSS 0.46%
Updated Jul 21, 2026
Linkace
Parameter Value
CVSS 8.1 (HIGH)
Fixed In 2.5.6
Type CWE-74 (Injection)
Vendor Linkace
Public PoC No

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on uninitialized LinkAce instances accepts attacker-controlled database credential fields and writes them back into .env without escaping. A remote attacker who can reach the setup endpoints and supply a database they control can inject mail configuration variables and achieve command execution when the application later sends mail.

This vulnerability is fixed in 2.5.6.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)