File Upload Vulnerability in PsiTransfer by Psi4ward
CVE-2026-41180

7.5HIGH

Key Information:

Vendor

Psi-4ward

Vendor
CVE Published:
23 April 2026

What is CVE-2026-41180?

PsiTransfer, an open source file sharing solution, has a vulnerability in its upload process that allows unauthenticated attackers to create files in the application root. Specifically, the flaw occurs in versions prior to 2.4.3 due to improper validation of request paths. An attacker can exploit this by manipulating the upload request, leading to the potential execution of malicious files upon application restart. Users are urged to update to version 2.4.3 or later to mitigate this risk.

Affected Version(s)

psitransfer < 2.4.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.