CVE-2026-54414 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-54414 requires immediate attention.
· 7 min read
Executive Summary
Urgent: CVE-2026-54414 is a critical path traversal flaw in FileRise before 3.16.0 that can let an attacker write arbitrary files outside the intended upload directory through the shared-folder upload endpoint /api/folder/uploadToSharedFolder.php. In the worst case, this can be used to overwrite account data and achieve administrator takeover; depending on deployment details, it may also lead to remote code execution.
The issue is especially dangerous for solo developers and small teams because the vulnerable feature is designed for public sharing: an attacker only needs a valid, non-expired, upload-enabled shared-folder link/token. There is no known exploitation in the wild and it is not in KEV, but the severity is still CRITICAL (CVSS 9.8). FileRise 3.16.0 fixes the bug by URL-decoding before validation and rejecting path separators in upload filenames.
Immediate Action
- Upgrade FileRise to 3.16.0 or later immediately. If you cannot patch right away, disable shared-folder uploads or take the upload service offline until remediation is complete.
- Revoke and rotate all shared-folder links/tokens, especially any public or long-lived upload links.
- Audit for suspicious file writes outside the upload directory, especially
users/users.txtor other account/auth files. - Back up current data and configs before upgrading, then verify the fix in a staging environment first if possible.
- Check the vendor advisory / release notes: Vendor advisory placeholder
- Temporarily isolate the service behind VPN, IP allowlists, or basic auth if you must keep it online during remediation.
Affected Versions
FileRise < 3.16.0vulnerable to path traversal in shared-folder uploads.FileRise 3.16.0+safe, based on the described fix.- If you vendor FileRise in a container or appliance, treat any image or package built from
< 3.16.0as vulnerable.
Resolution Guide
Primary fix: upgrade to the patched release and rotate shared-folder tokens afterward.
# Generic upgrade example
# TODO: replace with your deployment method
file-rise upgrade 3.16.0
JavaScript / npm / yarn / pnpm if FileRise is packaged as a dependency in your stack:
npm i filerise@^3.16.0
yarn add filerise@^3.16.0
pnpm add filerise@^3.16.0
Python / pip / pipx if installed as a Python package:
pip install --upgrade filerise>=3.16.0
pipx upgrade filerise
Java / Maven / Gradle if embedded in a Java service:
<dependency>
<groupId>TODO.groupId</groupId>
<artifactId>filerise</artifactId>
<version>3.16.0</version>
</dependency>
./gradlew dependencies
# then bump the FileRise artifact to 3.16.0+ in build.gradle
Linux package managers if distributed as a system package:
sudo apt-get update
sudo apt-get install --only-upgrade filerise
# or
sudo yum update filerise
Docker:
docker pull TODO_REGISTRY/filerise:3.16.0
docker stop filerise
docker rm filerise
docker run -d --name filerise TODO_REGISTRY/filerise:3.16.0
Hardening while you patch:
# Disable shared-folder uploads if your deployment supports it
SHARED_FOLDER_UPLOADS=false
# Or restrict upload endpoint access at the reverse proxy
location /api/folder/uploadToSharedFolder.php {
deny all;
}
Minimal code-level fix pattern: ensure decoding happens before validation, and reject any path separators after decoding.
$name = urldecode($fileName);
if (str_contains($name, '/') || str_contains($name, '\\')) {
throw new RuntimeException('Invalid filename');
}
$base = basename($name);
if (!preg_match(REGEX_FILE_NAME, $base)) {
throw new RuntimeException('Invalid filename');
}
Detection & Verification
Check your version:
grep -R "3\.16\.0" /opt/filerise /var/www /srv 2>/dev/null
php -r 'echo "TODO: replace with FileRise version check\n";'
Look for vulnerable code patterns:
grep -R "urldecode(basename" /path/to/filerise
grep -R "move_uploaded_file" /path/to/filerise
grep -R "uploadToSharedFolder.php" /path/to/filerise
Dependency and image auditing:
npm audit
pip-audit
mvn dependency:tree
./gradlew dependencies
docker image inspect TODO_REGISTRY/filerise:TAG
Verify the fix: after upgrading, test that filenames containing encoded traversal are rejected and do not write outside the upload directory.
# Expected: reject or sanitize
curl -F 'file=@test.txt;filename=..%2fusers%2fusers.txt' \
'https://YOUR-HOST/api/folder/uploadToSharedFolder.php?token=TODO'
# Confirm no file was written outside the upload directory
find /path/to/uploads -type f | sort
test -f /path/to/app/users/users.txt && echo "Unexpected write!"
Operational checks: review logs for upload requests with encoded separators such as %2f, %5c, ..%2f, or unusual writes to account-related files.
Risk and Impact
This flaw can turn a simple shared upload link into a full application compromise. An attacker who has a valid upload token may overwrite files outside the upload directory, including account data used to create or replace an administrator account. In some deployments, that level of write access can be chained into remote code execution, making the blast radius the entire FileRise host and any data reachable from it.