Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the intended authentication boundary for file push creation. This issue has been patched in versions 1.69.3 and 2.4.2.
References
| Link | Resource |
|---|---|
| https://github.com/pglombardo/PasswordPusher/commit/45dc2512875231ef45ecd5dfc8c3c8185f882bf4 | Patch |
| https://github.com/pglombardo/PasswordPusher/pull/4381 | Issue Tracking Patch |
| https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-qfh8-f79c-x86c | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-05-08 15:16
Updated : 2026-06-17 10:46
NVD link : CVE-2026-41308
Mitre link : CVE-2026-41308
CVE.ORG link : CVE-2026-41308
JSON object : View
Products Affected
apnotic
- password_pusher
CWE
