FileBrowser是filebrowser团队开源的一个文件管理界面,在指定的目录,它可以用来上传、删除、预览和编辑文件。 File Browser 2.63.6之前版本存在路径遍历漏洞,该漏洞源于构建下载压缩包时使用filepath.ToSlash处理文件名,导致包含Windows风格路径遍历字符的文件名被原样作为压缩条目名称,Windows解压工具将反斜杠解释为路径分隔符,可能将文件写入提取目录之外的位置,导致受害者下载并解压时遭受任意文件写入攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| filebrowser | filebrowser | < 2.63.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| filebrowser | filebrowser | < 2.63.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54089 | 9.1 CRITICAL | File Browser: Authentication Bypass via Proxy Auth Header Forgery |
| CVE-2026-54096 | 8.4 HIGH | File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existe |
| CVE-2026-55667 | 8.2 HIGH | File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-followin |
| CVE-2026-54094 | 7.5 HIGH | File Browser: Symlink following lets scoped users read, overwrite, and share files outside |
| CVE-2026-54091 | 7.5 HIGH | File Browser: Incorrect access control in public directory shares via rule path rebasing |
| CVE-2026-54092 | 6.5 MEDIUM | File Browser: DoS Vulnerability on Public Login API |
| CVE-2026-54090 | File Browser: Command Allowlist Bypass via Shell Metacharacter Injection | |
| CVE-2026-54088 | File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentica | |
| CVE-2026-54097 | File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in De |
No comments yet