CVE 6.5 MEDIUM

Password Pusher: JSON API `/p.json` file upload alias bypasses file-push authentication_CVE-2026-41308

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Description

Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the intended authentication boundary for file push creation. This issue has been patched in versions 1.69.3 and 2.4.2.

Basic Information

ID CVE-2026-41308
Source GitHub_M
Published May 8, 2026 at 14:30

Affected Product

Vendor pglombardo
Product PasswordPusher
Version < 1.69.3
Affected Versions pglombardo PasswordPusher < 1.69.3
pglombardo PasswordPusher >= 2.0.0-a, < 2.4.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.