CVE-2026-34745

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/uploadChunked endpoint but was not applied to the unauthenticated /api/uploadChunked/public endpoint in the same file (app/server/fireshare/api.py). An unauthenticated attacker can exploit the checkSum parameter to write arbitrary files with attacker-controlled content to any writable path on the server filesystem. This issue has been patched in version 1.5.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:shaneisrael:fireshare:*:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) Fireshare facilita el intercambio de medios y enlaces autoalojados. Antes de la versión 1.5.3, la corrección para CVE-2026-33645 se aplicó al endpoint autenticado /API/uploadChunked pero no se aplicó al endpoint no autenticado /API/uploadChunked/public en el mismo archivo (app/server/fireshare/api.py). Un atacante no autenticado puede explotar el parámetro checkSum para escribir archivos arbitrarios con contenido controlado por el atacante en cualquier ruta escribible en el sistema de archivos del servidor. Este problema ha sido parcheado en la versión 1.5.3.

03 Apr 2026, 19:50

Type Values Removed Values Added
CPE cpe:2.3:a:shaneisrael:fireshare:*:*:*:*:*:*:*:*
First Time Shaneisrael fireshare
Shaneisrael
References () https://github.com/ShaneIsrael/fireshare/commit/b76915607924756e6fa1a5f6c8823c38d611fb24 - () https://github.com/ShaneIsrael/fireshare/commit/b76915607924756e6fa1a5f6c8823c38d611fb24 - Patch
References () https://github.com/ShaneIsrael/fireshare/pull/520 - () https://github.com/ShaneIsrael/fireshare/pull/520 - Issue Tracking, Patch
References () https://github.com/ShaneIsrael/fireshare/releases/tag/v1.5.3 - () https://github.com/ShaneIsrael/fireshare/releases/tag/v1.5.3 - Release Notes
References () https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-fvvp-rj8g-c7gc - () https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-fvvp-rj8g-c7gc - Exploit, Mitigation, Vendor Advisory

02 Apr 2026, 19:21

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 19:21

Updated : 2026-07-24 21:10


NVD link : CVE-2026-34745

Mitre link : CVE-2026-34745

CVE.ORG link : CVE-2026-34745


JSON object : View

Products Affected

shaneisrael

  • fireshare
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')