CVE-2025-60538
Moderate
Shiori is vulnerable to authentication bypass via a brute force attack in github.com/go-shiori/shiori
Shiori is vulnerable to authentication bypass via a brute force attack in github.com/go-shiori/shiori
Exploit probability
0.4%
Published
January 13, 2026
Required by
Not available
Last source change
March 3, 2026
02 / AFFECTED SOFTWARE
Affected packages
29 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2025-60538
View original source
A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack.
Open Source Vulnerabilities
GO-2026-4308
View original source
Shiori is vulnerable to authentication bypass via a brute force attack in github.com/go-shiori/shiori
Open Source Vulnerabilities
GHSA-mw8h-g64c-rxv4
View original source
A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack.
05 / REFERENCES