<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:pictshare:pictshare:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3apictsharepictshare/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 22:18:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3apictsharepictshare/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure and Unauthorized File Deletion in PictShare</title><link>https://feed.craftedsignal.io/briefs/2026-10-pictshare-info-disclosure/</link><pubDate>Thu, 01 Oct 2026 22:18:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-pictshare-info-disclosure/</guid><description>PictShare versions prior to 3.7.1 are vulnerable to an unauthenticated information disclosure flaw in the API::info() endpoint, allowing attackers to retrieve sensitive metadata and delete arbitrary files.</description><content:encoded><![CDATA[<p>PictShare versions prior to 3.7.1 contain an information disclosure vulnerability in the API::info() endpoint. The application fails to implement a field whitelist when returning metadata objects via this API. As a result, unauthenticated attackers can supply a file hash to the endpoint to retrieve the complete metadata object. This object contains highly sensitive information, including the secret 'delete_code', the original uploader's IP address, User Agent string, remote port, and the file's SHA-1 hash. The exposure of the 'delete_code' presents a significant security risk, as an attacker can use this value to invoke the application's delete API to permanently remove arbitrary files from the server, leading to a loss of data integrity and system availability. Defenders should prioritize patching this vulnerability by upgrading to version 3.7.1 or later.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target PictShare instance accessible over the network.</li>
<li>Attacker gathers publicly accessible file hashes from the application's front-end or through reconnaissance.</li>
<li>Attacker sends a crafted HTTP GET or POST request to the API::info() endpoint, including a target file hash in the request parameters.</li>
<li>The application processes the request and returns the full, unfiltered metadata object associated with the hash to the unauthenticated attacker.</li>
<li>Attacker parses the JSON or raw response to extract the 'delete_code' and sensitive uploader metadata (IP, User Agent).</li>
<li>Attacker sends a secondary request to the application's delete API endpoint, providing the extracted 'delete_code'.</li>
<li>The application validates the 'delete_code' and proceeds to permanently delete the requested file.</li>
<li>Successful deletion results in a permanent loss of content availability and potential privacy impact for the original uploader.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in unauthorized information disclosure of user metadata and the ability for unauthenticated attackers to perform arbitrary file deletions. This compromises both user privacy and the availability of data hosted on the affected PictShare instance. The vulnerability carries a CVSS v3.1 base score of 8.2, reflecting its severity in environments where data availability is critical.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all PictShare instances to version 3.7.1 or later immediately to address CVE-2026-104051.</li>
<li>Implement network-level access controls to restrict exposure of the PictShare API endpoints to untrusted networks.</li>
<li>Review web server logs for high volumes of requests to the API::info() endpoint followed by requests to the delete API, which may indicate exploitation attempts.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>information-disclosure</category><category>api-vulnerability</category><category>cve-2026-104051</category></item></channel></rss>