File Upload Vulnerability in PsiTransfer by Psi4ward
CVE-2026-41180
7.5HIGH
What is CVE-2026-41180?
PsiTransfer, an open source file sharing solution, has a vulnerability in its upload process that allows unauthenticated attackers to create files in the application root. Specifically, the flaw occurs in versions prior to 2.4.3 due to improper validation of request paths. An attacker can exploit this by manipulating the upload request, leading to the potential execution of malicious files upon application restart. Users are urged to update to version 2.4.3 or later to mitigate this risk.
Affected Version(s)
psitransfer < 2.4.3
