{"id":"CVE-2026-104051","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-104051","summary":"PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info()…","details":"PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.","published":"2026-10-01T22:17:00.833","modified":"2026-10-02T18:47:49.947","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/HaschekSolutions/pictshare/commit/ce5fc474e89769efeae25fee763894bcce3412e3","label":"HaschekSolutions/pictshare@ce5fc47"},"references":[{"type":"WEB","url":"https://github.com/HaschekSolutions/pictshare/commit/ce5fc474e89769efeae25fee763894bcce3412e3"},{"type":"WEB","url":"https://github.com/HaschekSolutions/pictshare/releases/tag/v3.7.1"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/pictshare-sensitive-information-disclosure-via-info-api"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T18:47:49.947"}}