CVE-2026-54091
Description
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, File Browser's public share handlers rebase the share owner's filesystem root to the shared directory and then evaluate descendant paths against the owner's global and per-user rules using the rebased relative path instead of the original path relative to the owner's scope. As a result, an attacker who knows a public directory share URL can access files and subdirectories that the owner explicitly blocked with rules, as long as those blocked paths are located underneath the shared directory. In the simplest case this is an unauthenticated information disclosure through GET /api/public/share/* and GET /api/public/dl/*. This vulnerability is fixed in 2.63.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/filebrowser/filebrowser/v2Go | < 2.63.6 | 2.63.6 |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
- Range: <= 1.11.0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-j9jx-hp4c-ghhhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-54091ghsaADVISORY
- github.com/filebrowser/filebrowser/commit/e07c59df0b850f5924d5b1683e8609661ddcf534nvdWEB
- github.com/filebrowser/filebrowser/releases/tag/v2.63.6nvdWEB
- github.com/filebrowser/filebrowser/security/advisories/GHSA-j9jx-hp4c-ghhhnvdWEB
News mentions
0No linked articles in our index yet.