Sceawere

Vulnerability Detail

CVE-2026-108555UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PairDrop IP Spoofing Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.2
Creation Date
3h ago
Vendor
schlagmichdoch
Product
PairDrop
Attack Type
Use of Less Trusted Source
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

PairDrop through 1.11.2 contains an IP spoofing vulnerability in Peer._setIP that allows remote attackers to join other networks' discovery rooms by supplying a forged cf-connecting-ip header. Attackers who know a victim's public IP can appear as a local device on self-hosted instances not behind Cloudflare to send or receive files.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.2",
  "pubDate": "2026-10-10T15:16:58.690Z",
  "pubdate": "2026-10-10T15:16:58.690Z",
  "executiveSummary": "PairDrop versions through 1.11.2 are susceptible to an IP spoofing vulnerability located within the Peer._setIP function. This flaw arises from the improper trust placed in the cf-connecting-ip HTTP header, which allows remote, unauthenticated attackers to manipulate their perceived network origin.\nBy successfully injecting a forged IP address, an attacker can circumvent discovery restrictions on self-hosted instances that are not configured behind a Cloudflare proxy. This allows the attacker to impersonate a local device, effectively joining a target's private discovery room.\nThe primary risk involves unauthorized data transmission, where an attacker can intercept, send, or receive files from victims who believe they are communicating with a legitimate local peer. Exploitation requires the attacker to possess knowledge of the victim's public IP address. This vulnerability poses a significant security risk for self-hosted instances that rely on IP-based segmentation for network isolation.",
  "technicalDetails": "The vulnerability originates in the Peer._setIP function, which is responsible for determining and assigning the IP address of a connected peer within the application. The logic fails to properly sanitize or validate the source of the IP address, instead relying heavily on the cf-connecting-ip HTTP header. In environments where the application is not protected by Cloudflare’s infrastructure, this header is entirely user-controlled and easily manipulated.\nAn attacker initiates the exploit by crafting a malicious HTTP request that includes the cf-connecting-ip header, populated with the specific public IP address of the intended victim. When the application processes this request, the Peer._setIP function reads the forged header and assigns the spoofed IP to the attacker's session object. Because the application uses this spoofed IP for network discovery and room membership logic, it treats the attacker as if they are originating from the victim's local network segment.\nThe attack flow proceeds as follows: 1) The attacker identifies a target PairDrop instance that is self-hosted and lacks the intended reverse-proxy headers filtering. 2) The attacker obtains the target's public IP address. 3) The attacker initiates a connection to the PairDrop instance while injecting the cf-connecting-ip header containing the victim's IP. 4) The application logic erroneously maps the attacker's session to the victim's network context. 5) Once the attacker is successfully placed in the target's discovery room, they gain the ability to interact with the victim's device as a trusted local entity.\nThis vulnerability effectively bypasses the intended network isolation of PairDrop, granting unauthorized remote access to file exchange channels. Since the application architecture assumes that IP-based proximity equates to a trusted connection, the impact involves the potential for data exfiltration or the injection of malicious files into a victim's workflow. The lack of secondary authentication or cryptographic validation for peer identity exacerbates the impact of this spoofing flaw, allowing an attacker to operate with the same privileges as a local network participant."
}
CVE-2026-108555: PairDrop IP Spoofing Vulnerability (MEDIUM Severity, CVSS: 4.2) | Sceawere