CVE-2026-104051: PictShare < 3.7.1 Sensitive Information Disclosure via info API
PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret deletecode and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the deletecode via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated remote attacker can exploit it. The attacker needs a publicly visible file hash to query the info API endpoint.
What information and impact result from exploitation?
The endpoint can disclose the secret delete_code along with uploader metadata including IP address, User Agent, remote port, and SHA-1 hash. An attacker who obtains the delete_code can call the delete API to permanently delete files.
Which deployments are affected?
PictShare versions before 3.7.1 are affected. The described attack does not require authentication or user interaction.
How can I determine whether a file may be exposed?
A file may be exposed if its hash is publicly visible and the instance runs a version before 3.7.1. In that condition, the info API can return the file's raw metadata object, including the delete_code.