Moderate severityNVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
CVE-2026-55668
Description
File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to create attacker-controlled files outside the user's scope. This issue is fixed in version 2.63.16.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/filebrowser/filebrowser/v2Go | < 2.63.16 | 2.63.16 |
Affected products
1- Range: <2.63.16
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-8wc8-hf36-mjh9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55668ghsaADVISORY
- github.com/filebrowser/filebrowser/commit/64511ce45e3be379e965f7f4fb0929a068d5bb81ghsax_refsource_MISCWEB
- github.com/filebrowser/filebrowser/releases/tag/v2.63.16ghsax_refsource_MISCWEB
- github.com/filebrowser/filebrowser/security/advisories/GHSA-8wc8-hf36-mjh9ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.