Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and subscribe to live comment updates without authentication or authorization checks.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Andrii-kryvoviaz
Andrii-kryvoviaz slink |
|
| Vendors & Products |
Andrii-kryvoviaz
Andrii-kryvoviaz slink |
Fri, 04 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and subscribe to live comment updates without authentication or authorization checks. | |
| Title | Slink before 1.12.3 Missing Authorization on Image Comment Endpoints | |
| First Time appeared |
Slinkapp
Slinkapp slink |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:slinkapp:slink:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Slinkapp
Slinkapp slink |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-04T14:32:07.795Z
Updated: 2026-09-04T17:45:58.601Z
Reserved: 2026-09-04T11:00:28.731Z
Link: CVE-2026-85605
Updated: 2026-09-04T17:45:55.570Z
Status : Received
Published: 2026-09-04T15:17:41.233
Modified: 2026-09-04T18:18:04.047
Link: CVE-2026-85605
No data.