Home

Description

Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the intended authentication boundary for file push creation. This issue has been patched in versions 1.69.3 and 2.4.2.

PUBLISHED Reserved 2026-04-20 | Published 2026-05-08 | Updated 2026-05-08 | Assigner GitHub_M




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Problem types

CWE-288: Authentication Bypass Using an Alternate Path or Channel

Product status

< 1.69.3
affected

>= 2.0.0-a, < 2.4.2
affected

References

github.com/...Pusher/security/advisories/GHSA-qfh8-f79c-x86c

github.com/pglombardo/PasswordPusher/pull/4381

github.com/...ommit/45dc2512875231ef45ecd5dfc8c3c8185f882bf4

cve.org (CVE-2026-41308)

nvd.nist.gov (CVE-2026-41308)

Download JSON