Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the intended authentication boundary for file push creation. This issue has been patched in versions 1.69.3 and 2.4.2.
References
| Link | Resource |
|---|---|
| https://github.com/pglombardo/PasswordPusher/commit/45dc2512875231ef45ecd5dfc8c3c8185f882bf4 | Patch |
| https://github.com/pglombardo/PasswordPusher/pull/4381 | Issue Tracking Patch |
| https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-qfh8-f79c-x86c | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
05 Jun 2026, 00:26
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:pwpush:password_pusher:*:*:*:*:*:*:*:* |
cpe:2.3:a:apnotic:password_pusher:*:*:*:*:*:*:*:* |
| First Time |
Apnotic
Apnotic password Pusher |
14 May 2026, 18:03
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:pwpush:password_pusher:*:*:*:*:*:*:*:* cpe:2.3:a:pwpush:password_pusher:1.69.3:*:*:*:*:*:*:* |
|
| First Time |
Pwpush
Pwpush password Pusher |
|
| CWE | NVD-CWE-noinfo | |
| References | () https://github.com/pglombardo/PasswordPusher/commit/45dc2512875231ef45ecd5dfc8c3c8185f882bf4 - Patch | |
| References | () https://github.com/pglombardo/PasswordPusher/pull/4381 - Issue Tracking, Patch | |
| References | () https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-qfh8-f79c-x86c - Vendor Advisory |
08 May 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 15:16
Updated : 2026-06-05 00:26
NVD link : CVE-2026-41308
Mitre link : CVE-2026-41308
CVE.ORG link : CVE-2026-41308
JSON object : View
Products Affected
apnotic
- password_pusher
CWE
