CVE-2025-22137

CRITICAL

Pingvin Share <1.4.0 - Code Injection

Title source: llm
STIX 2.1

Description

Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) user to overwrite arbitrary files on the server, including sensitive system files, via HTTP POST requests. The issue has been patched in version 1.4.0.

Scores

CVSS v3 9.8
EPSS 0.0018
EPSS Percentile 39.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-434
Status published
Products (1)
stonith404/pingvin-share >= 0.6.0, < 1.4.0
Published Jan 08, 2025
Tracked Since Feb 18, 2026