GHSA-r72g-8wq6-6m7wHighCVSS 6.5

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the mercure-info endpoint to receive visit data including referrer, user agent, geolocation, and full short URL objects for URLs outside their authorization boundary.

🔗 References (7)