HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-66050 — NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its ...

·Source: NIST NVD

Updated:

Executive Summary

NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to a

Analysis

NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to arbitrary locations the current user has write access, including the Windows Startup folder, enabling persistent code execution on the next user login. CVSS Score: 7.5. Published: 2026-07-27T15:17:10.487.

Indicators of Compromise (1)

CVE (1)
CVE-2026-66050
Source Attribution

Originally published by NIST NVD on Jul 27, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerabilityNEW

Qualys Expands Serverless Security with Vulnerability Scanning for AWS Lambda

Key Takeaways Serverless functions have become a core building block for modern cloud and AI-native applications. With AWS Lambda, developers build and scale applications faster without managing underlying infrastructure. But as Lambda functions increasingly process sensitive data, connect to APIs, invoke AI services, and power critical workflows, securing the code and dependencies running inside

Qualys Blog
HIGHVulnerability

NVD HIGH: CVE-2026-66396 — SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List val...

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary code in the Electron renderer with full Node.js access when victims open affected documents.

CVE-2026-66396
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-66395 — SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerabi...

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering in an insecurely configured Electron renderer.

CVE-2026-66395
NIST NVD