Password‑Protected Thumbnail Bypass

GHSA : https://github.com/FlintSH/Flare/security/advisories/GHSA-3x7v-x3r6-mjh7

CVE : CVE-2026-30230

Summary

The thumbnail endpoint does not validate the password for password‑protected files. It checks ownership/admin for private files but skips password verification, allowing thumbnail access without the password.

Affected Component

Evidence (Code References)

Video POC

Impact

Expected vs Actual

Reproduction Checklist

Consider aligning thumbnail checks with the download/raw endpoints for consistent behavior.

Verification Checklist


Revision #3
Created 2026-03-02 14:20:33 UTC by Aryma
Updated 2026-03-06 01:21:49 UTC by Aryma