PT-2026-29874 · Fireshare · Fireshare

·

CVE-2026-34745

·

Published

2026-04-02

·

Updated

2026-04-03

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fireshare versions prior to 1.5.3
Description Fireshare allows self-hosted media and link sharing. Prior to version 1.5.3, a flaw existed in the /api/uploadChunked/public endpoint where an unauthenticated attacker could manipulate the checkSum parameter to write arbitrary files with attacker-controlled content to any writable path on the server filesystem. The fix for a related issue was applied to the authenticated /api/uploadChunked endpoint but not to the unauthenticated one. This allows for remote code execution.
Recommendations Update to version 1.5.3 or later.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34745
GHSA-FVVP-RJ8G-C7GC

Affected Products

Fireshare