Junglewise Threat Intelligence

CVE-2026-34745: ShaneIsrael Fireshare path traversal in public upload API

CVE-2026-34745 · Severity: critical · CVSS 9.1 · Published 2026-04-02

Technologies: Shaneisrael Fireshare. Vendors: Shaneisrael.

Executive brief

Fireshare, a self-hosted media and link sharing platform, contains a critical security flaw in its public upload feature. An unauthenticated attacker can exploit this to write or overwrite files anywhere on the server's filesystem. This could lead to a complete system takeover, data loss through file overwriting, or a total service outage.

Technical details

A path traversal vulnerability exists in the unauthenticated `/api/uploadChunked/public` endpoint in `app/server/fireshare/api.py`. The `checkSum` parameter is used in `os.path.join()` without sanitization or path validation, allowing an attacker to escape the intended upload directory using `../` sequences. By providing a malicious `checkSum` and a file blob, an attacker can write arbitrary content to any writable path on the server. This can be leveraged for Remote Code Execution (RCE) by overwriting application modules or system configuration files. This issue is a regression/omission where a previous fix for CVE-2026-33645 was applied to the authenticated endpoint but not the public one. The vulnerability is patched in version 1.5.3.

Affected products

  • ShaneIsrael Fireshare < 1.5.3

Timeline

  • 2026-03-30: patched: Fix merged and version 1.5.3 released.
  • 2026-03-30: advisory: Vendor security advisory published.
  • 2026-04-02: disclosed: CVE-2026-34745 published to NVD.

References

Related threats