VYPR
Moderate severityNVD Advisory· Published Mar 19, 2026· Updated Mar 20, 2026

File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter

CVE-2026-32758

Description

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.2 and below are vulnerable to Path Traversal through the resourcePatchHandler (http/resource.go). The destination path in resourcePatchHandler is validated against access rules before being cleaned/normalized, while the actual file operation calls path.Clean() afterward—resolving .. sequences into a different effective path. This allows an authenticated user with Create or Rename permissions to bypass administrator-configured deny rules (both prefix-based and regex-based) by injecting .. sequences in the destination parameter of a PATCH request. As a result, the user can write or move files into any deny-rule-protected path within their scope. However, this cannot be used to escape the user's BasePathFs scope or read from restricted paths. This issue has been fixed in version 2.62.0.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/filebrowser/filebrowser/v2Go
< 2.62.02.62.0

Affected products

1

Patches

1
4bd7d69c8216

fix: clean path in patch handler

https://github.com/filebrowser/filebrowserHenrique DiasMar 14, 2026via ghsa
1 file changed · +2 0
  • http/resource.go+2 0 modified
    @@ -212,6 +212,8 @@ func resourcePatchHandler(fileCache FileCache) handleFunc {
     		dst := r.URL.Query().Get("destination")
     		action := r.URL.Query().Get("action")
     		dst, err := url.QueryUnescape(dst)
    +		dst = path.Clean("/" + dst)
    +		src = path.Clean("/" + src)
     		if !d.Check(src) || !d.Check(dst) {
     			return http.StatusForbidden, nil
     		}
    

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

5

News mentions

0

No linked articles in our index yet.