External risk intelligence

Fireshare Vulnerable to Remote Code Execution via Malicious Filename Upload.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-67728

Fireshare is a self-hosted media and link sharing application. Such applications are commonly deployed as internet-facing services to facilitate content sharing. While the vulnerability can be triggered by an authenticated user, it is also reachable by unauthenticated users when the public uploads feature is enabled, making it a likely candidate for public-internet exposure.

Path Traversal

Shaneisrael Fireshare

before 1.3.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Fireshare, a self-hosted media and link sharing application, which could allow attackers to execute commands on affected systems. The issue arises from how filenames are handled during uploads, potentially leading to unauthorized access or remote code execution.

  • Malicious filenames can control system commands.
  • Critical issue allows remote system takeover.
  • Confirm relevance and assess exposure risk.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by crafting a malicious filename for a video upload. This crafted filename is then directly used in a system command, allowing the attacker to either move files to unauthorized locations or execute arbitrary commands on the server. This could be achieved by an unauthenticated user if public uploads are enabled, or by any authenticated user.

  • Requires unauthenticated or authenticated access.
  • Uploading a video with a crafted filename.
  • Remote code execution and arbitrary file upload.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a malicious filename could allow an attacker to upload files to arbitrary directories or execute system commands, potentially affecting the confidentiality, integrity, and availability of the Fireshare service.

  • System commands and files.
  • Crafted filename during upload.
  • Remote code execution and data compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Fireshare application's vendor and platform teams are primarily responsible for addressing this vulnerability. The initial step involves identifying all instances of Fireshare within the environment, determining their exposure, and confirming their business criticality to prioritize remediation efforts. This includes assessing whether the affected versions are publicly accessible or used internally, and then coordinating with the accountable owners for an appropriate response.

  • Own the issue: Application and platform teams.
  • Verify first: Confirm Fireshare instances and exposure.
  • Action: Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Fireshare?

Fireshare is a software application designed for self-hosting media and link sharing. Users deploy it to manage, store, and distribute video content and various links from their own infrastructure rather than relying on third-party cloud hosting platforms.

How does CVE-2025-67728 allow code execution?

This vulnerability is classified as Improper Neutralization of Special Elements used in a Command, or CWE-77. It occurs because the application takes a user-supplied filename during a video upload and inserts it directly into a system command without proper sanitization. This allows an attacker to inject additional commands that the server then executes.

Do I need to be logged in to trigger this vulnerability?

Not necessarily. While an authenticated user can trigger the bug, it is also reachable by unauthenticated users if the 'Public Uploads' feature is enabled in the Fireshare settings. If 'Public Uploads' is disabled, only authenticated users possess the ability to initiate the problematic upload process.

Is my Fireshare instance at risk?

According to Halo Surface Signal, Fireshare instances are commonly deployed as internet-facing services to allow broad content sharing, making them highly accessible to remote attackers. If your instance is reachable from the public internet, the potential for unauthorized access is significant regardless of whether it is used for internal or public purposes.

When should I update Fireshare?

You should prioritize updating immediately to version 1.3.0, which contains the fix for this issue. First, perform an inventory to locate all running instances of Fireshare in your environment, assess their current network exposure, and coordinate with the team responsible for those systems to apply the update.

References