CVE-2026-54544
Deferred Deferred - Pending Action

Outbound HTTP Requests in Fireshare via Unauthenticated API Endpoints

Vulnerability report for CVE-2026-54544, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-discord-webhook or POST /api/test-webhook and cause the Fireshare server to issue an arbitrary HTTP POST to any URL the attacker supplies, including internal network addresses and cloud metadata services. No credentials, session cookies, or prior access are required. Version 1.6.16 contains a patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-30
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fireshare fireshare to 1.6.16 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Fireshare before version 1.6.16 has two API endpoints without authentication checks. Attackers can send POST requests to /api/test-discord-webhook or /api/test-webhook to force the server to make arbitrary HTTP POST requests to any URL, including internal systems or cloud services. No prior access is needed.

Detection Guidance

Check Fireshare server logs for unusual POST requests to /api/test-discord-webhook or /api/test-webhook from unauthenticated sources. Monitor outbound HTTP traffic from the Fireshare server to unexpected destinations, especially internal network addresses or cloud metadata services.

Impact Analysis

An attacker could exploit this to send requests to internal systems, exfiltrate data, or interact with cloud metadata services. This may lead to unauthorized access, data leaks, or service disruption. Systems relying on Fireshare could be compromised without user interaction.

Compliance Impact

This vulnerability could violate GDPR by enabling unauthorized data exfiltration or HIPAA by exposing protected health information. Organizations may fail compliance due to insufficient access controls and potential data breaches.

Mitigation Strategies

Upgrade Fireshare to version 1.6.16 or later to apply the patch. If immediate upgrade is not possible, restrict network access to the vulnerable endpoints or block outbound HTTP requests from the Fireshare server until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54544. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart