Unrated severityNVD Advisory· Published Jul 12, 2026· Updated Jul 14, 2026
filebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete
CVE-2026-61874
Description
filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the dormant public share URL.
Affected products
1- Range: <2.63.17
Patches
Vulnerability mechanics
References
3- github.com/filebrowser/filebrowser/commit/be23ab3a15bf957928ecfed88de5ab67850c1b9cmitrepatch
- github.com/filebrowser/filebrowser/security/advisories/GHSA-pp88-jhwj-5qh5mitrevendor-advisory
- www.vulncheck.com/advisories/filebrowser-before-stale-public-share-via-trailing-slash-deletemitrethird-party-advisory
News mentions
0No linked articles in our index yet.