Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, to craft a malicious filename when uploading a video file. The malicious filename is then concatenated directly into a shell command, which can be used for uploading files to arbitrary directories via path traversal, or executing system commands for Remote Code Execution (RCE). This issue is fixed in version 1.3.0.
History

Fri, 12 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 07:15:00 +0000

Type Values Removed Values Added
Description Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, to craft a malicious filename when uploading a video file. The malicious filename is then concatenated directly into a shell command, which can be used for uploading files to arbitrary directories via path traversal, or executing system commands for Remote Code Execution (RCE). This issue is fixed in version 1.3.0.
Title Fireshare Public Uploads feature is vulnerable to OS Command Injection (RCE)
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-12T07:10:55.980Z

Updated: 2025-12-12T20:40:29.507Z

Reserved: 2025-12-10T20:04:28.289Z

Link: CVE-2025-67728

cve-icon Vulnrichment

Updated: 2025-12-12T20:40:24.642Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-12T07:15:45.250

Modified: 2025-12-12T15:17:31.973

Link: CVE-2025-67728

cve-icon Redhat

No data.