Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-62382 PoC — PasswordPusher before v2.9.6 Authentication Bypass via Null Comparison

Source
Associated Vulnerability
Title: PasswordPusher before v2.9.6 Authentication Bypass via Null Comparison (CVE-2026-62382)
Description:PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true, so the check passes and the deletable_by_viewer restriction is never enforced. An attacker who knows only the secret URL can permanently delete an anonymous push even when the creator disabled viewer deletion and even without the passphrase. Only deployments that allow anonymous pushes (the default) are affected. The issue is fixed in v2.9.6.
Description
PasswordPusher v1.45.11 through v2.9.5 allows unauthenticated deletion of anonymous pushes due to a nil==nil ownership-check bypass (CWE-863). The deletion guard evaluates (@push.user == current_user) || @push.deletable_by_viewer. For anonymous pushes, @push.user is nil; for unauthenticated requests, current_user is nil. Ruby evaluates nil==nil as true, so the ownership check passes and the deletable_by_viewer=false restriction is completely bypassed. Anyone who knows the secret URL token can permanently expire an anonymous push without any credentials.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →