CVE-2026-66050

Source
https://cve.org/CVERecord?id=CVE-2026-66050
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66050.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-66050
Published
2026-07-27T14:19:10.801Z
Modified
2026-07-28T04:03:13.338349811Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
NitroShare Desktop 0.3.4 Path Traversal via LAN File Transfer Server
Details

NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to arbitrary locations the current user has write access, including the Windows Startup folder, enabling persistent code execution on the next user login.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66050.json"
}
References

Affected packages

Git / github.com/nitroshare/nitroshare-desktop

Affected ranges

Type
GIT
Repo
https://github.com/nitroshare/nitroshare-desktop
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.3.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.3.0
0.3.0beta1
0.3.0beta2
0.3.1
0.3.2
0.3.3
0.3.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66050.json"