CVE-2026-33645
Last modified
CVE-2026-33645 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked upload endpoint allows an attacker to write arbitrary files outside the intended upload directory. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked upload endpoint allows an attacker to write arbitrary files outside the intended upload directory. The `checkSum` multipart field is used directly in filesystem path construction without sanitization or containment checks. This enables unauthorized file writes to attacker-chosen paths writable by the Fireshare process (e.g., container `/tmp`), violating integrity and potentially enabling follow-on attacks depending on deployment. Version 1.5.2 fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Shaneisrael | Fireshare | 1.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33645?
How severe is CVE-2026-33645?
How do I fix CVE-2026-33645?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33638Ech0 is an open-source, self-hosted publishing platform for …5.3
- CVE-2026-33640Outline is a service that allows for collaborative documenta…9.8
- CVE-2026-33641Glances is an open-source system cross-platform monitoring t…7.8
- CVE-2026-33642Kitty is a cross-platform GPU based terminal. In versions 0.…9.8
- CVE-2026-33643SQL Injection vulnerability in SchemaHero 0.23.0 via the col…7.4
- CVE-2026-33644Lychee is a free, open-source photo-management tool. Prior t…4.3
- CVE-2026-33646mise manages dev tools like node, python, cmake, and terrafo…9.6
- CVE-2026-33647WWBN AVideo is an open source video platform. In versions up…8.8
- CVE-2026-33648WWBN AVideo is an open source video platform. In versions up…8.8
- CVE-2026-33649WWBN AVideo is an open source video platform. In versions up…8.8
- CVE-2026-33650WWBN AVideo is an open source video platform. In versions up…7.6
- CVE-2026-33651WWBN AVideo is an open source video platform. In versions up…8.8
Are you affected by CVE-2026-33645?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
