CVE-2026-54337: Fireshare has Unauthenticated Argument Injection to Arbitrary File Write/Overwrite
Published Sep 15, 2026
·Updated
Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.
Affected Software
1 affected component
Fireshare<1.6.14
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.6.14
Event History
Sep 15, 2026
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Fireshare deployments are affected?
Fireshare versions prior to 1.6.14 are affected. Version 1.6.14 fixes the issue.
2
Does exploiting this issue require an account or user interaction?
No. The vulnerability is exploitable by an unauthenticated attacker and requires no user interaction.
3
What access does an attacker gain through successful exploitation?
A successful attacker can write or overwrite system files through argument injection in the video upload function.