PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in src/inc/core.php. Attackers can predict or infer the PRNG state to guess valid delete_code values and perform unauthorized deletion of hosted files without needing to read the code from the info endpoint.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains README.md (5,647 bytes) and demo.php (2,985 bytes), totaling 8,632 bytes of supplied file content. No repository URL, git reference, archive path, or archive size was provided; size_bytes is therefore recorded as 0 for unavailable metadata. This is a standalone PHP proof of concept, not a framework module. README.md describes a claimed CWE-338 vulnerability in PictShare: public file hashes and deletion authorization tokens are generated from the same non-cryptographic rand() stream. demo.php reproduces the token-generation function, seeds a simulated victim with 1337, and brute-forces a deliberately bounded seed space using the observed 12-character hash. It then advances the recovered generator past that hash and predicts the next 32-character token. This demonstrates deterministic prediction under controlled conditions, not universal remote state recovery or practical token recovery from an arbitrary public hash. The local attack vector reflects the implemented demonstration; the network vector reflects the documented potential for unauthenticated deletion on a vulnerable deployment. No network requests, deletion requests, shell payloads, persistence, or exfiltration are implemented. Documentation links point to project, advisory, CVE, badge, release, and commit pages; none are contacted by the code. The README reports remediation in PictShare 3.7.1 through replacement of rand() with random_int(), and references CVE-2026-104051 as a separate token-disclosure issue rather than an implemented target. CVE publication, affected versions, vendor confirmation, and fix claims cannot be independently verified from the supplied files.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.