{"id":"GHSA-xrjc-c68j-hp7w","summary":"PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI","details":"## Vulnerability Details\n\nA reflected JSON injection allows an attacker to return arbitrary data in the JSON endpoints (like ` /?jsonld=` and `/?pasteid`).\n\n### Root Cause\n\n`Request::getRequestUri()` sanitizes `$_SERVER['REQUEST_URI']` with `FILTER_SANITIZE_URL`:\n\n```php\npublic function getRequestUri()\n{\n    $uri = array_key_exists('REQUEST_URI', $_SERVER) ? filter_var($_SERVER['REQUEST_URI'], FILTER_SANITIZE_URL) : '';\n    return empty($uri) ? '/' : $uri;\n}\n```\n\n`FILTER_SANITIZE_URL` does **not** strip `\"`, `'`, `\u003c`, `\u003e` characters (per the PHP manual's allowed-character list for this filter). So the raw, attacker-controlled request URI (including query string) passes through almost unmodified into `Controller::$_urlBase` (set in `_init()`).\n\nIn `Controller::_jsonld()`, `$_urlBase` is spliced directly into one of the static `.jsonld` templates (`js/types.jsonld`, `js/paste.jsonld`, etc.) with a plain `str_replace()`, without any JSON-escaping:\n\n```php\n$content = str_replace(\n    '?jsonld=',\n    $this-\u003e_urlBase . '?jsonld=',\n    file_get_contents($file)\n);\n...\nheader('Content-type: application/ld+json');\nheader('Access-Control-Allow-Origin: *');\nheader('Access-Control-Allow-Methods: GET');\necho $content;\n```\n\nA request URI containing a literal `\"` therefore breaks out of the JSON string in the `\"@context\".\"pb\"` value and injects arbitrary attacker-controlled key/value pairs into the response body, which is served with `Content-Type: application/ld+json` and `Access-Control-Allow-Origin: *`.\n\nAdditionally, the `jsonld` case in `Controller::__construct()` returns early:\n\n```php\ncase 'jsonld':\n    $this-\u003e_jsonld($this-\u003e_request-\u003egetParam('jsonld'));\n    return;\n```\n\nThis bypasses `_setCacheHeaders()` and all of the security headers normally applied in `_view()` (notably `X-Content-Type-Options: nosniff`, CSP, `X-Frame-Options`, `Referrer-Policy`). So this is the only response path lacking `X-Content-Type-Options: nosniff`.\n\n### Attack Scenario\n1. An attacker crafts a request to the target PrivateBin instance whose request-target contains a raw `\"` character, e.g.:\n   `GET /?jsonld=types&x=\"injected\":\"pwned\",\"y\":\" HTTP/1.1`\n   (delivered via a raw socket / HTTP client that doesn't normalize the request line — most browsers percent-encode `\"` in the address bar, but many HTTP libraries, proxies, and automated link-preview/structured-data crawlers do not).\n2. The server reflects the raw value into the JSON-LD response, producing a syntactically broken / attacker-extended JSON document.\n3. Because `Access-Control-Allow-Origin: *` is set and `X-Content-Type-Options: nosniff` is missing on this path, any origin can fetch and rely on this manipulated content, and the response loses the defense-in-depth MIME-sniffing protection applied everywhere else in the app.\n\n### Impact\nReflected, unauthenticated injection of attacker-controlled content into a CORS-open `application/ld+json` response, plus a missing `X-Content-Type-Options: nosniff` header on this single response path (present everywhere else). No direct script execution was demonstrated on current browsers (this content type is generally not HTML-sniffed), but it is a real output-encoding bug (CWE-116) and a defense-in-depth gap that could be exploited by structured-data consumers or in combination with other issues / less-strict clients.\n\n### Vulnerable Code\n```php\n$content = str_replace(\n    '?jsonld=',\n    $this-\u003e_urlBase . '?jsonld=',\n    file_get_contents($file)\n);\n...\nheader('Content-type: application/ld+json');\n```\n\n### Verification\nDynamically confirmed on v2.0.4 (commit `597a6f0`) via `php -S 127.0.0.1:8082 index.php`:\n\nRequest:\n```http\nGET /?jsonld=types&x=\"injected\":\"pwned\",\"y\":\" HTTP/1.1\nHost: 127.0.0.1:8082\nConnection: close\n```\n\nUnpatched response body (excerpt):\n```json\n\"pb\": \"/?jsonld=types&x=\"injected\":\"pwned\",\"y\":\"?jsonld=types#\"\n```\n— i.e. the `\"` characters are reflected raw, breaking the JSON structure, and `X-Content-Type-Options` is absent from the response headers.\n\nAfter applying the fix above, the same request returns:\n```json\n\"pb\": \"/?jsonld=types&x=\\\"injected\\\":\\\"pwned\\\",\\\"y\\\":\\\"?jsonld=types#\"\n```\nwith `X-Content-Type-Options: nosniff` present, and the existing `JsonApiTest::testJsonLd*` unit test expectations (`/?jsonld=...`) remain unchanged for normal requests.\n\n## Credits\n\nThis vulnerability was reported by Iaohkut, @alanturing881, which PrivateBin would like to thank for that.\nIn general, PrivateBin would like to thank everyone reporting issues and potential vulnerabilities to it.\n\nIf you think you have found a vulnerability or potential security risk, [we'd kindly ask you to follow our security policy](https://github.com/PrivateBin/PrivateBin/blob/master/SECURITY.md) and report it to us. PrivateBin then assess the report and will take the actions PrivateBin deem necessary to address it.","aliases":["CVE-2026-55891"],"modified":"2026-08-28T20:40:37.666522Z","published":"2026-08-28T20:25:34Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-116"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-08-28T20:25:34Z"},"references":[{"type":"WEB","url":"https://github.com/PrivateBin/PrivateBin/security/advisories/GHSA-xrjc-c68j-hp7w"},{"type":"WEB","url":"https://github.com/PrivateBin/PrivateBin/commit/75f056dcda955d94c17ec5a4f8c54a9b7bfcee07"},{"type":"PACKAGE","url":"https://github.com/PrivateBin/PrivateBin"},{"type":"WEB","url":"https://github.com/PrivateBin/PrivateBin/releases/tag/2.0.5"}],"affected":[{"package":{"name":"privatebin/privatebin","ecosystem":"Packagist","purl":"pkg:composer/privatebin/privatebin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.5"}]}],"versions":["1.0","1.1","1.1.1","1.2","1.2.1","1.2.2","1.2.3","1.3","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.4.0","1.5.0","1.5.1","1.5.2","1.6.0","1.6.1","1.6.2","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.7.5","1.7.6","1.7.7","1.7.8","1.7.9","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-xrjc-c68j-hp7w/GHSA-xrjc-c68j-hp7w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"}]}