Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the raw and direct file routes only block unauthenticated users from accessing private files. Any authenticated, non‑owner user who knows the file URL can retrieve the content, which is inconsistent with stricter checks used by other endpoints. This issue has been patched in version 1.7.2.
References
| Link | Resource |
|---|---|
| https://github.com/FlintSH/Flare/security/advisories/GHSA-gwqr-xf5c-5569 | Exploit Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-06 21:16
Updated : 2026-06-17 10:32
NVD link : CVE-2026-30231
Mitre link : CVE-2026-30231
CVE.ORG link : CVE-2026-30231
JSON object : View
Products Affected
flintsh
- flare
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
