VYPR

Filebrowser

by Filebrowser

Source repositories

CVEs (69)

  • CVE-2026-62843MedJul 15, 2026
    risk 0.37cvss 6.8epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as…

  • CVE-2026-54093MedJun 25, 2026
    risk 0.37cvss —epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, filebrowser builds the download-as-zip / download-as-tar archive entry names with filepath.ToSlash, which on a Linux host is…

  • CVE-2026-72838MedAug 14, 2026
    risk 0.35cvss 6.5epss 0.00

    FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the declared upload length to exhaust…

  • CVE-2026-54092MedJun 25, 2026
    risk 0.35cvss 6.5epss 0.01

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arbitrarily large password to be passed into the login API. This spikes CPU and…

  • CVE-2026-32761MedMar 20, 2026
    risk 0.35cvss 6.5epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.0 and below contain a permission enforcement bypass which allows users who are denied download privileges (perm.download =…

  • CVE-2026-32758MedMar 20, 2026
    risk 0.35cvss 6.5epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.2 and below are vulnerable to Path Traversal through the resourcePatchHandler (http/resource.go). The destination path in…

  • CVE-2026-28492MedMar 5, 2026
    risk 0.35cvss 6.5epss 0.00

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.0, when a user creates a public share link for a directory, the withHashFile middleware in http/public.go uses…

  • CVE-2026-55668MedJul 8, 2026
    risk 0.34cvss 6.3epss 0.00

    File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to…

  • CVE-2026-82235MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.00

    filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly request archives containing named…

  • CVE-2025-52997MedJun 30, 2025
    risk 0.31cvss 5.9epss 0.01

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers…

  • CVE-2025-52900MedJun 26, 2025
    risk 0.29cvss 5.5epss 0.00

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The file access permissions for files uploaded to or created from File Browser are never explicitly set by the application. The same…

  • CVE-2026-25889MedFeb 9, 2026
    risk 0.28cvss 5.4epss 0.00

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, a case-sensitivity flaw in the password validation logic allows any authenticated user to change their password (or…

  • CVE-2026-54685MedJul 20, 2026
    risk 0.27cvss 5.3epss 0.00

    FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a `401`/`403` response almost…

  • CVE-2026-23849MedJan 19, 2026
    risk 0.27cvss 5.3epss 0.00

    File Browser provides a file managing interface within a specified directory and can be used to upload, delete, preview, rename, and edit files. Prior to version 2.55.0, the JSONAuth. Auth function contains a logic flaw that allows unauthenticated attackers to enumerate valid…

  • CVE-2025-52901MedJun 30, 2025
    risk 0.22cvss 4.5epss 0.01

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.9, access tokens are used as GET parameters. The JSON Web Token (JWT) which is used as a session identifier…

  • CVE-2026-72834MedAug 14, 2026
    risk 0.21cvss 4.3epss 0.00

    filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest and returns it without performing a Perm.Download check (unlike the sibling raw, preview, and…

  • CVE-2026-82238LowAug 28, 2026
    risk 0.20cvss 3.1epss 0.00

    filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests at the same offset to bypass…

  • CVE-2025-52996LowJun 30, 2025
    risk 0.20cvss 3.1epss 0.00

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions 2.32.0 and prior, the implementation of password protected links is error-prone, resulting in potential unprotected…

  • CVE-2026-82237LowAug 28, 2026
    risk 0.13cvss 3.1epss 0.00

    filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path is empty). When any new, unrelated file…

  • CVE-2026-82236LowAug 28, 2026
    risk 0.13cvss 3.1epss 0.00

    File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.