VYPR
Moderate severityNVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026

File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope

CVE-2026-55668

Description

File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to create attacker-controlled files outside the user's scope. This issue is fixed in version 2.63.16.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/filebrowser/filebrowser/v2Go
< 2.63.162.63.16

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.