CVE-2026-54414 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-54414 requires immediate attention.

· 7 min read

Executive Summary

Urgent: CVE-2026-54414 is a critical path traversal flaw in FileRise before 3.16.0 that can let an attacker write arbitrary files outside the intended upload directory through the shared-folder upload endpoint /api/folder/uploadToSharedFolder.php. In the worst case, this can be used to overwrite account data and achieve administrator takeover; depending on deployment details, it may also lead to remote code execution.

The issue is especially dangerous for solo developers and small teams because the vulnerable feature is designed for public sharing: an attacker only needs a valid, non-expired, upload-enabled shared-folder link/token. There is no known exploitation in the wild and it is not in KEV, but the severity is still CRITICAL (CVSS 9.8). FileRise 3.16.0 fixes the bug by URL-decoding before validation and rejecting path separators in upload filenames.

Immediate Action

  • Upgrade FileRise to 3.16.0 or later immediately. If you cannot patch right away, disable shared-folder uploads or take the upload service offline until remediation is complete.
  • Revoke and rotate all shared-folder links/tokens, especially any public or long-lived upload links.
  • Audit for suspicious file writes outside the upload directory, especially users/users.txt or other account/auth files.
  • Back up current data and configs before upgrading, then verify the fix in a staging environment first if possible.
  • Check the vendor advisory / release notes: Vendor advisory placeholder
  • Temporarily isolate the service behind VPN, IP allowlists, or basic auth if you must keep it online during remediation.

Affected Versions

  • FileRise < 3.16.0 vulnerable to path traversal in shared-folder uploads.
  • FileRise 3.16.0+ safe, based on the described fix.
  • If you vendor FileRise in a container or appliance, treat any image or package built from < 3.16.0 as vulnerable.

Resolution Guide

Primary fix: upgrade to the patched release and rotate shared-folder tokens afterward.

# Generic upgrade example
# TODO: replace with your deployment method
file-rise upgrade 3.16.0

JavaScript / npm / yarn / pnpm if FileRise is packaged as a dependency in your stack:

npm i filerise@^3.16.0
yarn add filerise@^3.16.0
pnpm add filerise@^3.16.0

Python / pip / pipx if installed as a Python package:

pip install --upgrade filerise>=3.16.0
pipx upgrade filerise

Java / Maven / Gradle if embedded in a Java service:

<dependency>
  <groupId>TODO.groupId</groupId>
  <artifactId>filerise</artifactId>
  <version>3.16.0</version>
</dependency>
./gradlew dependencies
# then bump the FileRise artifact to 3.16.0+ in build.gradle

Linux package managers if distributed as a system package:

sudo apt-get update
sudo apt-get install --only-upgrade filerise
# or
sudo yum update filerise

Docker:

docker pull TODO_REGISTRY/filerise:3.16.0
docker stop filerise
docker rm filerise
docker run -d --name filerise TODO_REGISTRY/filerise:3.16.0

Hardening while you patch:

# Disable shared-folder uploads if your deployment supports it
SHARED_FOLDER_UPLOADS=false

# Or restrict upload endpoint access at the reverse proxy
location /api/folder/uploadToSharedFolder.php {
  deny all;
}

Minimal code-level fix pattern: ensure decoding happens before validation, and reject any path separators after decoding.

$name = urldecode($fileName);
if (str_contains($name, '/') || str_contains($name, '\\')) {
    throw new RuntimeException('Invalid filename');
}
$base = basename($name);
if (!preg_match(REGEX_FILE_NAME, $base)) {
    throw new RuntimeException('Invalid filename');
}

Detection & Verification

Check your version:

grep -R "3\.16\.0" /opt/filerise /var/www /srv 2>/dev/null
php -r 'echo "TODO: replace with FileRise version check\n";'

Look for vulnerable code patterns:

grep -R "urldecode(basename" /path/to/filerise
grep -R "move_uploaded_file" /path/to/filerise
grep -R "uploadToSharedFolder.php" /path/to/filerise

Dependency and image auditing:

npm audit
pip-audit
mvn dependency:tree
./gradlew dependencies
docker image inspect TODO_REGISTRY/filerise:TAG

Verify the fix: after upgrading, test that filenames containing encoded traversal are rejected and do not write outside the upload directory.

# Expected: reject or sanitize
curl -F 'file=@test.txt;filename=..%2fusers%2fusers.txt' \
  'https://YOUR-HOST/api/folder/uploadToSharedFolder.php?token=TODO'

# Confirm no file was written outside the upload directory
find /path/to/uploads -type f | sort
test -f /path/to/app/users/users.txt && echo "Unexpected write!"

Operational checks: review logs for upload requests with encoded separators such as %2f, %5c, ..%2f, or unusual writes to account-related files.

Risk and Impact

This flaw can turn a simple shared upload link into a full application compromise. An attacker who has a valid upload token may overwrite files outside the upload directory, including account data used to create or replace an administrator account. In some deployments, that level of write access can be chained into remote code execution, making the blast radius the entire FileRise host and any data reachable from it.

Keep reading