File Browser是File Browser开源的一个文件管理界面,在指定的目录,它可以用来上传,删除,预览和编辑文件。 File Browser 2.63.1之前版本存在安全漏洞,该漏洞源于代理身份验证处理程序未应用与注册处理程序相同的修复,导致通过代理身份验证首次登录自动创建的用户被授予执行能力,可能导致权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| filebrowser | filebrowser | < 2.63.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-35585 | File Browser has a Command Injection via Hook Runner | |
| CVE-2026-35604 | File Browser share links remain accessible after Share/Download permissions are revoked | |
| CVE-2026-35606 | File Browser discloses text file content via /api/resources endpoint bypassing Perm.Downlo | |
| CVE-2026-35605 | File Browser has an access rule bypass via HasPrefix without trailing separator in path ma |
No comments yet