Impact
PairDrop through 1.11.2 contains an IP spoofing vulnerability in the Peer._setIP function. A remote attacker can supply a forged cf-connecting-ip header to force the application to treat the request as if it originated from a specified IP address. The result is that the attacker can join other networks' discovery rooms and appear as a local device on self-hosted instances that are not protected behind Cloudflare. This misuse is constrained to file-transfer functions but allows an attacker to impersonate a local peer.
Affected Systems
The vulnerability affects schlagmichdoch’s PairDrop software up to version 1.11.2. Any server running this version and exposing the discovery service will be susceptible, particularly when it is self-hosted and not behind a trusted reverse proxy such as Cloudflare. The flaw does not require elevated privileges on the target; it is triggered simply by sending crafted HTTP requests containing a cf-connecting-ip header.
Risk and Exploitability
The CVSS score is 2.3, indicating low overall severity. Exploitability is high as it requires only remote header tampering, which is trivial for an attacker with internet connectivity. No exploit convictions or known public exploits have been reported, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can use the flaw to spoof local peers, potentially enabling lateral movement within the discovery network or unauthorized file transfers. Given its low severity, the risk to confidentiality, integrity, or availability is limited, but it remains exploitable without restrictions.
OpenCVE Enrichment