Executive brief
PasswordPusher is an open-source application used to securely share sensitive information and files via temporary links. A security flaw allowed unauthenticated users to upload files through the application's API, even when the system was configured to require login for such actions. While this does not directly expose existing private data, it could allow unauthorized individuals to consume server storage and bandwidth, potentially leading to increased costs or service instability.
Technical details
An authentication bypass vulnerability (CWE-288) exists in PasswordPusher's API endpoints. Specifically, the `Api::V1::PushesController#create` path failed to consistently enforce authentication for file-type pushes when certain anonymous creation settings were enabled. An unauthenticated remote attacker could exploit this by sending a specially crafted JSON API request to create a file push, bypassing intended access controls. This allows for unauthorized file uploads, leading to potential storage exhaustion and bandwidth consumption. The issue has been resolved by implementing stricter authentication checks in the API controller and adding regression tests.
Affected products
- pglombardo PasswordPusher < 1.69.4, 2.0.0 - 2.4.1
Timeline
- 2026-04-14: patched: Fix committed to master branch
- 2026-04-17: advisory: Vendor security advisory published
- 2026-05-08: disclosed: CVE published to NVD