CVE-2026-90930
- EPSS 0.41%
- Veröffentlicht 14.09.2026 12:48:26
- Zuletzt bearbeitet 24.09.2026 20:44:42
File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-denied files by...
CVE-2026-90929
- EPSS 0.3%
- Veröffentlicht 14.09.2026 12:48:25
- Zuletzt bearbeitet 24.09.2026 20:44:42
File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler does not reject a target that is a...
CVE-2026-90928
- EPSS 0.3%
- Veröffentlicht 14.09.2026 12:48:24
- Zuletzt bearbeitet 24.09.2026 20:44:42
File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of l...
CVE-2026-90927
- EPSS 0.25%
- Veröffentlicht 14.09.2026 12:48:24
- Zuletzt bearbeitet 24.09.2026 20:34:34
filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages to exhaust s...
CVE-2026-82238
- EPSS 0.17%
- Veröffentlicht 28.08.2026 10:49:27
- Zuletzt bearbeitet 30.09.2026 18:18:41
filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests...
CVE-2026-82237
- EPSS 0.17%
- Veröffentlicht 28.08.2026 10:49:26
- Zuletzt bearbeitet 24.09.2026 20:34:34
filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path is empty). ...
CVE-2026-82236
- EPSS 0.28%
- Veröffentlicht 28.08.2026 10:49:25
- Zuletzt bearbeitet 30.09.2026 18:18:40
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path...
CVE-2026-82235
- EPSS 0.39%
- Veröffentlicht 28.08.2026 10:49:25
- Zuletzt bearbeitet 24.09.2026 20:34:34
filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly reques...
CVE-2026-62684
- EPSS 0.39%
- Veröffentlicht 18.08.2026 15:20:10
- Zuletzt bearbeitet 18.09.2026 20:09:01
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandler, and share...
CVE-2026-72838
- EPSS 0.3%
- Veröffentlicht 14.08.2026 11:35:42
- Zuletzt bearbeitet 08.09.2026 20:32:39
FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the decla...