Aller au contenu

Fiche vulnérabilité

CVE-2026-33645 : faille élevée shaneisrael fireshare (CVSS 8.1)

Description

Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked upload endpoint allows an attacker to write arbitrary files outside the intended upload directory. The `checkSum` multipart field is used directly in filesystem path construction without sanitization or containment checks. This enables unauthorized file writes to attacker-chosen paths writable by the Fireshare process (e.g., container `/tmp`), violating integrity and potentially enabling follow-on attacks depending on deployment. Version 1.5.2 fixes the issue.

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 mars 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • shaneisrael fireshare

Références

Rechercher une autre vulnérabilité dans la base CVE