Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and subscribe to live comment updates without authentication or authorization checks.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and subscribe to live comment updates without authentication or authorization checks. | |
| Title | Slink before 1.12.3 Missing Authorization on Image Comment Endpoints | |
| First Time appeared |
Slinkapp
Slinkapp slink |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:slinkapp:slink:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Slinkapp
Slinkapp slink |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T17:45:58.601Z
Reserved: 2026-09-04T11:00:28.731Z
Link: CVE-2026-85605
No data.
Status : Received
Published: 2026-09-04T15:17:41.233
Modified: 2026-09-04T15:17:41.233
Link: CVE-2026-85605
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:30:07Z
Weaknesses