Junglewise Threat Intelligence

CVE-2026-62382: PasswordPusher improper authorization in push deletion

CVE-2026-62382 · Severity: info · CVSS 6.9 · Published 2026-08-22

Technologies: PasswordPusher.

Executive brief

PasswordPusher is a web application that securely shares sensitive information via temporary links with optional passphrases and expiration controls. A flaw in the ownership check for deleting anonymous pushes allows any unauthenticated user with the secret URL to permanently destroy the shared secret—even if the creator explicitly disabled viewer deletion and protected it with a passphrase. This bypasses a core availability guarantee of the service.

Technical details

This is an improper authorization vulnerability (CWE-863) in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values evaluate to nil, and Ruby evaluates nil == nil as true, causing the check to pass and the deletable_by_viewer restriction to be bypassed. The vulnerability exists in both the REST API and web controller destroy/expire actions. An unauthenticated attacker who knows only the secret URL can trigger the expire! method, which irreversibly clears the payload, passphrase, and attachments. No authentication, credentials, or passphrase knowledge is required. The issue was introduced in v1.45.11 by a commit that replaced explicit user_signed_in? branching with a nil comparison. The fix is available in v2.9.6, which re-adds proper guards for the anonymous case.

Affected products

  • PasswordPusher PasswordPusher v1.45.11 through v2.9.5

Timeline

  • 2026-08-07: disclosed: GitHub Security Advisory GHSA-jf2m-hpj9-4qx2 published
  • 2026-08-22: patched: v2.9.6 released with fix

References