๐Ÿ” CVE Alert

CVE-2026-55891

UNKNOWN 0.0

PrivateBin: Reflected JSON injection in backend responses via unescaped REQUEST_URI

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which does not remove quotation marks, angle brackets, or apostrophes, and Controller::_init() stores the attacker-controlled value in Controller::$_urlBase. Controller::_jsonld() in lib/Controller.php then uses str_replace() to insert that value without JSON escaping into js/types.jsonld, js/paste.jsonld, and the other JSON-LD templates used by /?jsonld= and /?pasteid. A raw quotation mark delivered by an HTTP client, proxy, or structured-data crawler that does not normalize the request target can break out of the JSON string and inject arbitrary key-value data into a CORS-open application/ld+json response. The jsonld branch in Controller::__construct() returns before _setCacheHeaders(), so the response also lacks X-Content-Type-Options: nosniff, Content Security Policy, X-Frame-Options, and Referrer-Policy. Direct script execution was not demonstrated, but manipulated responses can affect structured-data consumers or combine with less strict clients. This issue is fixed in version 2.0.5.

CWE CWE-116
Vendor privatebin
Product privatebin
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for privatebin privatebin

Be the first to know when new unknown vulnerabilities affecting privatebin privatebin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
None

Affected Versions

PrivateBin / PrivateBin
< 2.0.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/PrivateBin/PrivateBin/security/advisories/GHSA-xrjc-c68j-hp7w github.com: https://github.com/PrivateBin/PrivateBin/commit/164c839c39688533ef0086575878e8392cd21249 github.com: https://github.com/PrivateBin/PrivateBin/releases/tag/2.0.5