CVE Explorer
CVE-2026-41308
Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the intended authentication boundary for file push creation. This issue has been patched in versions 1.69.3 and 2.4.2.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"PasswordPusher","vendor":"pglombardo","versions":[{"status":"affected","version":"< 1.69.3"},{"status":"affected","version":">= 2.0.0-a, < 2.4.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ae2d41e3fe78d4414e43aca70623b5cd32fcf66fcf75295f7f40b1411a768561 · sha256:9f1d7b5335aadf5f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ae2d41e3fe78d4414e43aca70623b5cd32fcf66fcf75295f7f40b1411a768561 · sha256:9f1d7b5335aadf5f… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-288","description":"CWE-288: Authentication Bypass Using an Alternate Path or Channel","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ae2d41e3fe78d4414e43aca70623b5cd32fcf66fcf75295f7f40b1411a768561 · sha256:9f1d7b5335aadf5f… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/pglombardo/PasswordPusher/commit/45dc2512875231ef45ecd5dfc8c3c8185f882bf4","tags":["x_refsource_MISC"],"url":"https://github.com/pglombardo/PasswordPusher/commit/45dc2512875231ef45ecd5dfc8c3c8185f882bf4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ae2d41e3fe78d4414e43aca70623b5cd32fcf66fcf75295f7f40b1411a768561 · sha256:9f1d7b5335aadf5f… · /containers/cna/references/2
{"name":"https://github.com/pglombardo/PasswordPusher/pull/4381","tags":["x_refsource_MISC"],"url":"https://github.com/pglombardo/PasswordPusher/pull/4381"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ae2d41e3fe78d4414e43aca70623b5cd32fcf66fcf75295f7f40b1411a768561 · sha256:9f1d7b5335aadf5f… · /containers/cna/references/1
{"name":"https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-qfh8-f79c-x86c","tags":["x_refsource_CONFIRM"],"url":"https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-qfh8-f79c-x86c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ae2d41e3fe78d4414e43aca70623b5cd32fcf66fcf75295f7f40b1411a768561 · sha256:9f1d7b5335aadf5f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.