Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/uploadChunked endpoint but was not applied to the unauthenticated /api/uploadChunked/public endpoint in the same file (app/server/fireshare/api.py). An unauthenticated attacker can exploit the checkSum parameter to write arbitrary files with attacker-controlled content to any writable path on the server filesystem. This issue has been patched in version 1.5.3.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:shaneisrael:fireshare:*:*:*:*:*:*:*:* |
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shaneisrael
Shaneisrael fireshare |
|
| Vendors & Products |
Shaneisrael
Shaneisrael fireshare |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/uploadChunked endpoint but was not applied to the unauthenticated /api/uploadChunked/public endpoint in the same file (app/server/fireshare/api.py). An unauthenticated attacker can exploit the checkSum parameter to write arbitrary files with attacker-controlled content to any writable path on the server filesystem. This issue has been patched in version 1.5.3. | |
| Title | Unauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/public | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-02T19:15:43.377Z
Reserved: 2026-03-30T19:17:10.224Z
Link: CVE-2026-34745
Updated: 2026-04-02T19:15:39.896Z
Status : Analyzed
Published: 2026-04-02T19:21:33.340
Modified: 2026-04-03T19:50:08.803
Link: CVE-2026-34745
No data.
OpenCVE Enrichment
Updated: 2026-04-03T09:16:37Z