/Vulnerability Library

PasswordPusher v1.45.11-v2.9.5 - Unauthenticated Anonymous Push Deletion via Ownership Bypass

CVE-2026-62382
Verified

Description

PasswordPusher v1.45.11 through v2.9.5 allows unauthenticated deletion of anonymous pushes due to a nil==nil ownership-check bypass (CWE-863). The deletion guard evaluates (@push.user == current_user) || @push.deletable_by_viewer. For anonymous pushes, @push.user is nil; for unauthenticated requests, current_user is nil. Ruby evaluates nil==nil as true, so the ownership check passes and the deletable_by_viewer=false restriction is completely bypassed. Anyone who knows the secret URL token can permanently expire an anonymous push without any credentials.

Severity

Medium

CVSS Score

6.9

Exploit Probability

1%

Affected Product

passwordpusher

Published Date

September 15, 2026

Template Author

dhiyaneshdk

CVE-2026-62382.yaml
6.9Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CVE ID:
cve-2026-62382
CWE ID:
cwe-863

References

https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-jf2m-hpj9-4qx2https://nvd.nist.gov/vuln/detail/CVE-2026-62382

Remediation Steps

Upgrade PasswordPusher to v2.9.6 or later.