ZeroHour

CVE-2026-54337

niche

Unauthenticated Argument Injection in Fireshare Video Upload Overwrites System Files

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Fireshare, a self-hosted media and link sharing application, contains an argument injection flaw (CWE-88) in its video upload function in all versions prior to 1.6.14. An unauthenticated remote attacker can inject additional arguments into the upload processing path by sending a crafted request to the affected endpoint, allowing them to write or overwrite arbitrary files on the host system. Because the endpoint requires no authentication and the flaw carries a CVSS 3.1 score of 9.8 (network vector, low complexity, no privileges, no user interaction), any internet-reachable instance can be fully compromised through file overwrite leading to code execution or data destruction. Operators running Fireshare below 1.6.14 are affected; the issue is fixed in version 1.6.14. There is no known public proof of concept and the CVE is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Upgrade Fireshare to version 1.6.14 or later immediately. Until patched, remove the instance from public internet exposure (e.g., restrict access via VPN, firewall rules, or a reverse proxy with authentication) and disable the video upload endpoint. Review the server for unexpectedly created or modified files outside the media directories and rotate any credentials or secrets stored on the host in case of prior compromise.

Affected
Fireshare project Fireshare (self-hosted media and link sharing)All versions prior to 1.6.14
Estimated exposure
nicheLikely tens to low hundreds of internet-exposed self-hosted instances; no reliable count available — Fireshare is a small open-source self-hosted application with no published install counts or public scan figures, so this is a qualitative estimate based on the project's limited adoption and typical self-hosting deployment patterns.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.

Weakness
CWE-88
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.