Pictshare · Pictshare · CVE-2026-104051
**Name of the Vulnerable Software and Affected Versions**
PictShare versions prior to 3.7.1
**Description**
An information disclosure issue exists where unauthenticated attackers can obtain the secret `delete code` and uploader metadata. This occurs when calling the 'API::info()' endpoint, which returns the complete raw metadata object without a field whitelist. By using a publicly visible file hash, an attacker can retrieve the `delete code` and subsequently use the delete API to permanently remove arbitrary files. Additionally, this exposes the uploader IP, User Agent, remote port, and SHA-1 hash, compromising content integrity, availability, and uploader privacy.
**Recommendations**
Update PictShare to version 3.7.1 or later.
Restrict access to the 'API::info()' endpoint to minimize the risk of metadata exposure.