CVE-2026-54337 is an argument-injection vulnerability in Fireshare's video-upload functionality. Fireshare versions earlier than 1.6.14 improperly neutralize argument delimiters passed during video upload processing, enabling a remote unauthenticated attacker to write or overwrite system files.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept for CVE-2026-54337 affecting Fireshare. It contains no standalone exploit program; instead, the exploit is documented in README.md and supported by a docker-compose.yml file for spinning up a test instance. The PoC demonstrates an unauthenticated file write/overwrite issue in Fireshare’s public upload functionality by sending a crafted multipart/form-data request to /api/upload/public. The attacker controls the uploaded filename and influences the destination directory through form fields, while disguising the upload as an .mp4 file. The stated impact is arbitrary overwrite within directories writable by the service account, especially /data, /processed, /images, and /videos; the README highlights overwriting /data/db.sqlite as a denial-of-service style outcome that can render the site unusable. Repository structure is simple: LICENSE, README.md with exploitation steps and caveats, and docker-compose.yml for local reproduction. There is no automation beyond the sample curl command, so this is best classified as a basic PoC rather than an operational or weaponized exploit.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.