fireshare vulnerabilities
CVEs whose affected-version data names the fireshare package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54544High· 7.2PoCFireshare facilitates self-hosted media and link sharing
Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-disco…
▾ MidnightShaneIsrael · fireshareEPSS 0.32%via NVD
CVE-2026-54337Critical· 9.8PoCFireshare facilitates self-hosted media and link sharing
Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.
▾ AbyssalShaneIsrael · fireshareEPSS 0.44%via NVD