CVE Explorer
CVE-2025-67728
Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, to craft a malicious filename when uploading a video file. The malicious filename is then concatenated directly into a shell command, which can be used for uploading files to arbitrary directories via path traversal, or executing system commands for Remote Code Execution (RCE). This issue is fixed in version 1.3.0.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"fireshare","vendor":"ShaneIsrael","versions":[{"status":"affected","version":"< 1.3.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2c47bbec3c60354bff82a41d60a3c300d2d8b5a03d2d13cd12712b6299da045d · sha256:43b33d4d45c86c86… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2c47bbec3c60354bff82a41d60a3c300d2d8b5a03d2d13cd12712b6299da045d · sha256:43b33d4d45c86c86… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-77","description":"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2c47bbec3c60354bff82a41d60a3c300d2d8b5a03d2d13cd12712b6299da045d · sha256:43b33d4d45c86c86… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/ShaneIsrael/fireshare/commit/157386c85f6683f89192dae52115069b435b6d34","tags":["x_refsource_MISC"],"url":"https://github.com/ShaneIsrael/fireshare/commit/157386c85f6683f89192dae52115069b435b6d34"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2c47bbec3c60354bff82a41d60a3c300d2d8b5a03d2d13cd12712b6299da045d · sha256:43b33d4d45c86c86… · /containers/cna/references/1
{"name":"https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-c4f5-g622-q72m","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-c4f5-g622-q72m"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2c47bbec3c60354bff82a41d60a3c300d2d8b5a03d2d13cd12712b6299da045d · sha256:43b33d4d45c86c86… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.