CVE-2026-33645General(shaneisrael / fireshare)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked upload endpoint allows an attacker to write arbitrary files outside the intended upload directory. The `checkSum` multipart field is used directly in filesystem path construction without sanitization or containment checks. This enables unauthorized file writes to attacker-chosen paths writable by the Fireshare process (e.g., container `/tmp`), violating integrity and potentially enabling follow-on attacks depending on deployment. Version 1.5.2 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fireshare

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-03)
  • 3 total mentions across 2 days

Affected systems

Products
fireshare

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-26: 1Mentions · 2026-04-03: 2Technical Details · 2026-03-26: 103-2604-03
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-04-032
General2
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-34745 Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/uploadChunked endpo… https://www.cve.org/CVERecord?id=CVE-2026-34745

    Post summary

    The text references CVE-2026-34745 in the context of Fireshare’s upload endpoint but provides no evidence of exploitation, patch, PoC, or technical details.

    00000144
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-34745 - Critical Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/uploadChunked endpoint but was not appli... https://www.thehackerwire.com/vulnerability/CVE-2026-34745/ https://t.co/RFXWLr83La

    Post summary

    The tweet merely notes the existence of CVE-2026-34745 as critical with minimal detail, lacking any PoC, exploit, or patch information.

    0000051
    163 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33645 Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked upload endpoint allow… https://www.cve.org/CVERecord?id=CVE-2026-33645

    Post summary

    The tweet announces an authenticated path traversal vulnerability (CVE‑2026‑33645) affecting Fireshare v1.5.1, providing technical details but no PoC, exploit, patch, or active exploitation evidence.

    0000057
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appshaneisraelfireshare1.5.1--

Explore more