---
id: CVE-2025-67728
title: Fireshare facilitates self-hosted media and link sharing
summary: >-
  Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and
  below allow an authenticated user, or unauthenticated user if the Public
  Uploads setting is enabled, to craft a malicious filename when uploading a
  video file.…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
vendor: shaneisrael
product: fireshare
affected:
  - fireshare < 1.3.0
patched:
  - fireshare 1.3.0
published: '2025-12-12'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67728'
references:
  - url: >-
      https://github.com/ShaneIsrael/fireshare/commit/157386c85f6683f89192dae52115069b435b6d34
    label: security-advisories@github.com
  - url: >-
      https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-c4f5-g622-q72m
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00686
epssPercentile: 0.51038
ingestedAt: '2026-10-07T20:46:46.895Z'
---

## Overview

Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, to craft a malicious filename when uploading a video file. The malicious filename is then concatenated directly into a shell command, which can be used for uploading files to arbitrary directories via path traversal, or executing system commands for Remote Code Execution (RCE). This issue is fixed in version 1.3.0.

## Affected

- `fireshare < 1.3.0`

## Remediation

Upgrade past the affected range:

- `fireshare 1.3.0`
