High severityNVD Advisory· Published Jul 15, 2026· Updated Jul 20, 2026
File Browser: Colliding username normalization gives two users the same home directory
CVE-2026-62685
Description
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new user scopes from usernames passed through cleanUsername() when Signup=true and CreateUserDir=true, but the many-to-one normalization can collapse usernames such as team/one, team one, and team-one to the same home directory without checking whether the resulting scope is already taken, allowing a second registrant to gain full read and write access to another user's files. This issue is fixed in version 2.63.17.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/filebrowser/filebrowser/v2Go | < 2.63.17 | 2.63.17 |
Affected products
1- Range: <2.63.17
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-7rc3-g7h6-22m7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-62685ghsaADVISORY
- github.com/filebrowser/filebrowser/commit/883a36f02fcb69566a8628cb47f18fdc73348387ghsax_refsource_MISCWEB
- github.com/filebrowser/filebrowser/releases/tag/v2.63.17ghsax_refsource_MISCWEB
- github.com/filebrowser/filebrowser/security/advisories/GHSA-7rc3-g7h6-22m7ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.