| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| linkace-v2.6.1.zip | 2026-08-04 | 21.3 MB | |
| linkace-v2.6.1-docker.zip | 2026-08-04 | 16.5 kB | |
| README.md | 2026-08-03 | 995 Bytes | |
| v2.6.1 source code.tar.gz | 2026-08-03 | 1.2 MB | |
| v2.6.1 source code.zip | 2026-08-03 | 1.7 MB | |
| Totals: 5 Items | 24.2 MB | 9 | |
This is an important security release which contains updated dependencies as well as the following fixes:
- Fixed a server-side request forgery (SSRF) issue where private/internal IP addresses could still be reached during metadata fetching due to inconsistent DNS resolution between the validator and the HTTP client.
- Fixed a CSV formula injection vulnerability in the bookmark export feature that could allow malicious spreadsheet formulas embedded in a link's title or description to execute when the exported file was opened.
- Fixed a stored XSS vulnerability where javascript: URLs could bypass URL validation during bookmark import and execute when a user clicked the imported link.
- Fixed a stored XSS vulnerability in Markdown-rendered links that could be used to trick an administrator into creating and leaking a privileged system API token.
- Fixed an information disclosure issue where HTML bookmark exports could reveal the names of private tags belonging to other users.