{"id":"CVE-2026-55891","title":"PrivateBin is an online pastebin where the server has zero knowledge of pasted data","summary":"PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which does not remove quotation …","severity":"low","cvss":0,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","cwe":["CWE-116"],"vendor":"privatebin","product":"privatebin/privatebin","affected":["privatebin/privatebin <= 2.0.4"],"patched":["privatebin/privatebin 2.0.5"],"published":"2026-08-28","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:09:13.080","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55891","references":[{"url":"https://github.com/PrivateBin/PrivateBin/commit/164c839c39688533ef0086575878e8392cd21249","label":"security-advisories@github.com"},{"url":"https://github.com/PrivateBin/PrivateBin/releases/tag/2.0.5","label":"security-advisories@github.com"},{"url":"https://github.com/PrivateBin/PrivateBin/security/advisories/GHSA-xrjc-c68j-hp7w","label":"security-advisories@github.com"},{"url":"https://github.com/PrivateBin/PrivateBin/security/advisories/GHSA-xrjc-c68j-hp7w","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/PrivateBin/PrivateBin/commit/75f056dcda955d94c17ec5a4f8c54a9b7bfcee07"},{"url":"https://github.com/advisories/GHSA-xrjc-c68j-hp7w"}],"tags":["nvd","ghsa","composer"],"epss":0.00539,"epssPercentile":0.42889,"aliases":["GHSA-xrjc-c68j-hp7w"],"ecosystem":"composer","ingestedAt":"2026-08-28T21:25:40.638Z","slug":"CVE-2026-55891","body":"## Overview\n\nPrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which does not remove quotation marks, angle brackets, or apostrophes, and Controller::_init() stores the attacker-controlled value in Controller::$_urlBase. Controller::_jsonld() in lib/Controller.php then uses str_replace() to insert that value without JSON escaping into js/types.jsonld, js/paste.jsonld, and the other JSON-LD templates used by /?jsonld= and /?pasteid. A raw quotation mark delivered by an HTTP client, proxy, or structured-data crawler that does not normalize the request target can break out of the JSON string and inject arbitrary key-value data into a CORS-open application/ld+json response. The jsonld branch in Controller::__construct() returns before _setCacheHeaders(), so the response also lacks X-Content-Type-Options: nosniff, Content Security Policy, X-Frame-Options, and Referrer-Policy. Direct script execution was not demonstrated, but manipulated responses can affect structured-data consumers or combine with less strict clients. This issue is fixed in version 2.0.5.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-55891)\n\nAffected packages:\n\n- `privatebin/privatebin <= 2.0.4`\n\nPatched in:\n\n- `privatebin/privatebin 2.0.5`\n\nSource: https://github.com/advisories/GHSA-xrjc-c68j-hp7w","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":201787,"id":"CVE-2026-55891","ts":1789399724331,"field":"cvss","old":null,"new":"0"},{"seq":200517,"id":"CVE-2026-55891","ts":1789397372356,"field":"cvss","old":"0","new":null},{"seq":198434,"id":"CVE-2026-55891","ts":1789391956772,"field":"cvss","old":null,"new":"0"},{"seq":196227,"id":"CVE-2026-55891","ts":1789383583846,"field":"cvss","old":"0","new":null},{"seq":195156,"id":"CVE-2026-55891","ts":1789380473580,"field":"cvss","old":null,"new":"0"},{"seq":193943,"id":"CVE-2026-55891","ts":1789378512798,"field":"cvss","old":"0","new":null},{"seq":192730,"id":"CVE-2026-55891","ts":1789376405448,"field":"cvss","old":null,"new":"0"},{"seq":191517,"id":"CVE-2026-55891","ts":1789373418306,"field":"cvss","old":"0","new":null},{"seq":190302,"id":"CVE-2026-55891","ts":1789369296532,"field":"cvss","old":null,"new":"0"},{"seq":189089,"id":"CVE-2026-55891","ts":1789368265594,"field":"cvss","old":"0","new":null},{"seq":187872,"id":"CVE-2026-55891","ts":1789365141843,"field":"cvss","old":null,"new":"0"},{"seq":186659,"id":"CVE-2026-55891","ts":1789363269855,"field":"cvss","old":"0","new":null},{"seq":185445,"id":"CVE-2026-55891","ts":1789361099723,"field":"cvss","old":null,"new":"0"},{"seq":184232,"id":"CVE-2026-55891","ts":1789358154284,"field":"cvss","old":"0","new":null},{"seq":182483,"id":"CVE-2026-55891","ts":1789354218295,"field":"cvss","old":null,"new":"0"},{"seq":181276,"id":"CVE-2026-55891","ts":1789353119141,"field":"cvss","old":"0","new":null},{"seq":180069,"id":"CVE-2026-55891","ts":1789350163438,"field":"cvss","old":null,"new":"0"},{"seq":178862,"id":"CVE-2026-55891","ts":1789348099721,"field":"cvss","old":"0","new":null},{"seq":177655,"id":"CVE-2026-55891","ts":1789346271758,"field":"cvss","old":null,"new":"0"},{"seq":176448,"id":"CVE-2026-55891","ts":1789343017386,"field":"cvss","old":"0","new":null},{"seq":174565,"id":"CVE-2026-55891","ts":1789334763613,"field":"cvss","old":null,"new":"0"},{"seq":173360,"id":"CVE-2026-55891","ts":1789333484423,"field":"cvss","old":"0","new":null},{"seq":172174,"id":"CVE-2026-55891","ts":1789331011446,"field":"cvss","old":null,"new":"0"},{"seq":170988,"id":"CVE-2026-55891","ts":1789328613095,"field":"cvss","old":"0","new":null},{"seq":169783,"id":"CVE-2026-55891","ts":1789327044950,"field":"cvss","old":null,"new":"0"},{"seq":168578,"id":"CVE-2026-55891","ts":1789323658309,"field":"cvss","old":"0","new":null},{"seq":167373,"id":"CVE-2026-55891","ts":1789319576342,"field":"cvss","old":null,"new":"0"},{"seq":166168,"id":"CVE-2026-55891","ts":1789318559032,"field":"cvss","old":"0","new":null},{"seq":164963,"id":"CVE-2026-55891","ts":1789315696843,"field":"cvss","old":null,"new":"0"},{"seq":163758,"id":"CVE-2026-55891","ts":1789313450427,"field":"cvss","old":"0","new":null},{"seq":162553,"id":"CVE-2026-55891","ts":1789311813486,"field":"cvss","old":null,"new":"0"},{"seq":161348,"id":"CVE-2026-55891","ts":1789308523218,"field":"cvss","old":"0","new":null},{"seq":160853,"id":"CVE-2026-55891","ts":1789304472991,"field":"cvss","old":null,"new":"0"},{"seq":160400,"id":"CVE-2026-55891","ts":1789303981808,"field":"cvss","old":"0","new":null},{"seq":159461,"id":"CVE-2026-55891","ts":1789300399766,"field":"cvss","old":null,"new":"0"},{"seq":158691,"id":"CVE-2026-55891","ts":1789299493789,"field":"cvss","old":"0","new":null},{"seq":157655,"id":"CVE-2026-55891","ts":1789296579044,"field":"cvss","old":null,"new":"0"},{"seq":156450,"id":"CVE-2026-55891","ts":1789294594746,"field":"cvss","old":"0","new":null},{"seq":155245,"id":"CVE-2026-55891","ts":1789292784798,"field":"cvss","old":null,"new":"0"},{"seq":154040,"id":"CVE-2026-55891","ts":1789289589208,"field":"cvss","old":"0","new":null},{"seq":152690,"id":"CVE-2026-55891","ts":1789281487802,"field":"cvss","old":null,"new":"0"},{"seq":152330,"id":"CVE-2026-55891","ts":1789281098283,"field":"cvss","old":"0","new":null},{"seq":151291,"id":"CVE-2026-55891","ts":1789277533802,"field":"cvss","old":null,"new":"0"},{"seq":150252,"id":"CVE-2026-55891","ts":1789276079060,"field":"cvss","old":"0","new":null},{"seq":149219,"id":"CVE-2026-55891","ts":1789273730254,"field":"cvss","old":null,"new":"0"},{"seq":148186,"id":"CVE-2026-55891","ts":1789271120405,"field":"cvss","old":"0","new":null},{"seq":146221,"id":"CVE-2026-55891","ts":1789269275767,"field":"cvss","old":null,"new":"0"},{"seq":142833,"id":"CVE-2026-55891","ts":1789261355117,"field":"cvss","old":"0","new":null},{"seq":141664,"id":"CVE-2026-55891","ts":1789258739397,"field":"cvss","old":null,"new":"0"},{"seq":140505,"id":"CVE-2026-55891","ts":1789256580938,"field":"cvss","old":"0","new":null}]}