PT-2026-28505 · Fireshare · Fireshare

Qiaonpc

·

Publicado

2026-03-26

·

Atualizado

2026-04-03

·

CVE-2026-33645

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fireshare versions prior to 1.5.2
Description Fireshare facilitates self-hosted media and link sharing. Version 1.5.1 contains an authenticated path traversal vulnerability in the chunked upload endpoint. The checkSum multipart field is used directly in filesystem path construction without sanitization or containment checks. This allows an attacker to write arbitrary files to attacker-chosen paths writable by the Fireshare process, such as the /tmp container, potentially enabling follow-on attacks depending on deployment. This compromises the integrity of the system.
Recommendations Update to version 1.5.2 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33645
GHSA-7Q8R-VPQ3-89M7

Produtos afetados

Fireshare