Password‑Protected Thumbnail Bypass
Flare Zero day Research
GHSA : https://github.com/FlintSH/Flare/security/advisories/GHSA-3x7v-x3r6-mjh7
CVE : CVE-2026-30230
Summary
The thumbnail endpoint does not validate the password for password‑protected files. It checks ownership/admin for private files but skips password veri...