Security Advisory

CVE-2026-41308

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-08 14:30:37
Last updated 2026-05-11 18:54:15
Assigner GitHub_M
CVSS score 6.5
State PUBLISHED

Description

Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the intended authentication boundary for file push creation. This issue has been patched in versions 1.69.3 and 2.4.2.