
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60538 is a missing rate-limiting vulnerability in Shiori, an open-source bookmark manager written in Go, that allows unauthenticated attackers to bypass authentication via brute force attacks against the login page. It affects Shiori v1.7.4 and all earlier versions. The vulnerability was reported on August 28, 2025, published to the NVD on January 9, 2026, and reviewed in the GitHub Advisory Database on January 13, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, Red Hat CVE).
The root cause is the absence of any rate limiting or account lockout mechanism on Shiori's login endpoint, classified as CWE-290 (Authentication Bypass by Spoofing). Because the application imposes no restriction on the number of login attempts, an unauthenticated remote attacker can submit an unlimited number of credential guesses over the network with low complexity and no user interaction required. The vulnerability was originally reported via a GitHub issue where the reporter demonstrated exploitation using Burp Suite's Intruder tool to automate credential stuffing against the login POST request (Shiori Issue, Github Advisory).
Successful exploitation allows an attacker to gain unauthorized access to a victim's Shiori account, exposing all stored bookmarks and any associated metadata, which may include sensitive or private URLs. The CVSS assessment reflects low confidentiality impact (access to bookmark data) and low availability impact, with no integrity impact noted. Since Shiori supports multiple user accounts and administrative roles, compromise of an admin account could affect all users of a shared instance (Github Advisory, Red Hat CVE).
No public proof-of-concept exploit code has been confirmed, and there is no evidence of active in-the-wild exploitation at this time. The attack requires no authentication, no special privileges, and no user interaction, making it trivially executable by any network-accessible attacker. The EPSS score is approximately 0.06% (0.018% per GitHub Advisory), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Red Hat CVE).
shiori)./api/v1/auth/login or equivalent) from a single IP or small range of IPs in a short time window; sequential or rapid-fire login attempts with varying password fields.The GitHub Advisory notes that no patched version has been formally designated as of the advisory's last update (January 13, 2026); however, Shiori v1.8.0 was released on September 26, 2025, and users should upgrade to the latest available release above v1.7.4 (Shiori Repo). As interim mitigations, administrators should deploy a reverse proxy or WAF (e.g., nginx, Cloudflare) in front of Shiori configured with rate limiting rules on the login endpoint, and consider restricting access to trusted IP ranges. Implementing account lockout or CAPTCHA at the network or application layer, and using strong, unique passwords for all accounts, will further reduce risk (Github Advisory, Red Hat CVE).
The vulnerability was reported by a community member (vityuasdop) via a GitHub issue on August 28, 2025, and labeled as a bug by the Shiori maintainers, though no public maintainer statement or patch announcement has been made specifically addressing this CVE. Red Hat has tracked the issue in their CVE database. Coverage has been limited to automated vulnerability aggregators and a brief write-up on infinitsec.net, with no significant broader media or researcher commentary observed (Shiori Issue, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."