{"id":"CVE-2026-55891","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-55891","summary":"PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI","details":"## Vulnerability Details\n\nA reflected JSON injection allows an attacker to return arbitrary data in the JSON endpoints (like ` /?jsonld=` and `/?pasteid`).\n\n### Root Cause\n\n`Request::getRequestUri()` sanitizes `$_SERVER['REQUEST_URI']` with `FILTER_SANITIZE_URL`:\n\n```php\npublic function getRequestUri()\n{\n    $uri = array_key_exists('REQUEST_URI', $_SERVER) ? filter_var($_SERVER['REQUEST_URI'], FILTER_SANITIZE_URL) : '';\n    return empty($uri) ? '/' : $uri;\n}\n```\n\n`FILTER_SANITIZE_URL` does **not** strip `\"`, `'`, `<`, `>` characters (per the PHP manual's allowed-character list for this filter). So the raw, attacker-controlled request URI (including query string) passes through almost unmodified into `Controller::$_urlBase` (set in `_init()`).\n\nIn `Controller::_jsonld()`, `$_urlBase` is spliced directly into one of the static `.jsonld` templates (`js/types.jsonld`, `js/paste.jsonld`, etc.) with a plain `str_replace()`, without any JSON-escaping:\n\n```php\n$content = str_replace(\n    '?jsonld=',\n    $this->_urlBase . '?jsonld=',\n    file_get_contents($file)\n);\n...\nheader('Content-type: application/ld+json');\nheader('Access-Control-Allow-Origin: *');\nheader('Access-Control-Allow-Methods: GET');\necho $content;\n```\n\nA request URI containing a literal `\"` therefore breaks out of the JSON string in the `\"@context\".\"pb\"` value and injects arbitrary attacker-controlled key/value pairs into the response body, which is served with `Content-Type: application/ld+json` and `Access-Control-Allow-Origin: *`.\n\nAdditionally, the `jsonld` case in `Controller::__construct()` returns early:\n\n```php\ncase 'jsonld':\n    $this->_jsonld($this->_request->getParam('jsonld'));\n    return;\n```\n\nThis bypasses `_setCacheHeaders()` and all of the security headers normally applied in `_view()` (notably `X-Content-Type-Options: nosniff`, CSP, `X-Frame-Options`, `Referrer-Policy`). So this is the only response path lacking `X-Content-Type-Options: nosniff`.\n\n### Attack Scenario\n1. An attacker crafts a request to the target PrivateBin instance whose request-target contains a raw `\"` character, e.g.:\n   `GET /?jsonld=types&x=\"injected\":\"pwned\",\"y\":\" HTTP/1.1`\n   (delivered via a raw socket / HTTP client that doesn't normalize the request line — most browsers percent-encode `\"` in the address bar, but many HTTP libraries, proxies, and automated link-preview/structured-data crawlers do not).\n2. The server reflects the raw value into the JSON-LD response, producing a syntactically broken / attacker-extended JSON document.\n3. Because `Access-Control-Allow-Origin: *` is set and `X-Content-Type-Options: nosniff` is missing on this path, any origin can fetch and rely on this manipulated content, and the response loses the defense-in-depth MIME-sniffing protection applied everywhere else in the app.\n\n### Impact\nReflected, unauthenticated injection of attacker-controlled content into a CORS-open `application/ld+json` response, plus a missing `X-Content-Type-Options: nosniff` header on this single response path (present everywhere else). No direct script execution was demonstrated on current browsers (this content type is generally not HTML-sniffed), but it is a real output-encoding bug (CWE-116) and a defense-in-depth gap that could be exploited by structured-data consumers or in combination with other issues / less-strict clients.\n\n### Vulnerable Code\n```php\n$content = str_replace(\n    '?jsonld=',\n    $this->_urlBase . '?jsonld=',\n    file_get_contents($file)\n);\n...\nheader('Content-type: application/ld+json');\n```\n\n### Verification\nDynamically confirmed on v2.0.4 (commit `597a6f0`) via `php -S 127.0.0.1:8082 index.php`:\n\nRequest:\n```http\nGET /?jsonld=types&x=\"injected\":\"pwned\",\"y\":\" HTTP/1.1\nHost: 127.0.0.1:8082\nConnection: close\n```\n\nUnpatched response body (excerpt):\n```json\n\"pb\": \"/?jsonld=types&x=\"injected\":\"pwned\",\"y\":\"?jsonld=types#\"\n```\n— i.e. the `\"` characters are reflected raw, breaking the JSON structure, and `X-Content-Type-Options` is absent from the response headers.\n\nAfter applying the fix above, the same request returns:\n```json\n\"pb\": \"/?jsonld=types&x=\\\"injected\\\":\\\"pwned\\\",\\\"y\\\":\\\"?jsonld=types#\"\n```\nwith `X-Content-Type-Options: nosniff` present, and the existing `JsonApiTest::testJsonLd*` unit test expectations (`/?jsonld=...`) remain unchanged for normal requests.\n\n## Credits\n\nThis vulnerability was reported by Iaohkut, @alanturing881, which PrivateBin would like to thank for that.\nIn general, PrivateBin would like to thank everyone reporting issues and potential vulnerabilities to it.\n\nIf you think you have found a vulnerability or potential security risk, [we'd kindly ask you to follow our security policy](https://github.com/PrivateBin/PrivateBin/blob/master/SECURITY.md) and report it to us. PrivateBin then assess the report and will take the actions PrivateBin deem necessary to address it.","published":"2026-08-28T20:25:34Z","modified":"2026-08-28T20:30:11.666275373Z","cvss":{"score":0,"severity":"NONE","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"privatebin/privatebin","fixedVersion":"2.0.5"}],"fix":{"url":"https://github.com/PrivateBin/PrivateBin/commit/75f056dcda955d94c17ec5a4f8c54a9b7bfcee07","label":"PrivateBin/PrivateBin@75f056d"},"references":[{"type":"WEB","url":"https://github.com/PrivateBin/PrivateBin/security/advisories/GHSA-xrjc-c68j-hp7w"},{"type":"WEB","url":"https://github.com/PrivateBin/PrivateBin/commit/75f056dcda955d94c17ec5a4f8c54a9b7bfcee07"},{"type":"PACKAGE","url":"https://github.com/PrivateBin/PrivateBin"},{"type":"WEB","url":"https://github.com/PrivateBin/PrivateBin/releases/tag/2.0.5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T20:30:11.666275373Z"}}