Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54544— Fireshare has unauthenticated SSRF via missing login_required on webhook test endpoints

Quick assessment

Affected
ShaneIsrael fireshare
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Fireshare 是一个用于自托管媒体和链接共享的平台。在版本 1.6.16 之前,两个触发出站 HTTP 请求的 API 端点缺少 装饰器,导致未经身份验证的攻击者可以调用 或 ,使 Fireshare 服务器向攻击者提供的任意 URL(包括内网地址和云元数据服务)发起任意的 HTTP POST 请求。该漏洞无需任何凭证、会话 Cookie 或预先访问权限即可利用。该问题已在版本 1.6.16 中修复。

CVSS 7.2 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54544

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Fireshare has unauthenticated SSRF via missing login_required on webhook test endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-discord-webhook or POST /api/test-webhook and cause the Fireshare server to issue an arbitrary HTTP POST to any URL the attacker supplies, including internal network addresses and cloud metadata services. No credentials, session cookies, or prior access are required. Version 1.6.16 contains a patch.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ShaneIsrael fireshare < 1.6.16 -

II. Public POCs for CVE-2026-54544

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54544

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54544 (1)

Vendor Advisories for CVE-2026-54544 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54544

No comments yet


Leave a comment