FileBrowser是filebrowser团队开源的一个文件管理界面,在指定的目录,它可以用来上传、删除、预览和编辑文件。 FileBrowser 2.63.6版本至2.63.16版本存在路径遍历漏洞,该漏洞源于归档构建器使用strings.ReplaceAll导致文件名替换问题,允许具有上传权限的用户植入反斜杠命名的文件,当其他用户下载并提取生成的zip或tar归档时,文件会逃逸提取目录。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| filebrowser | filebrowser | >= 2.63.6, < 2.63.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| filebrowser | filebrowser | >= 2.63.6, < 2.63.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62685 | 8.1 HIGH | File Browser: Colliding username normalization gives two users the same home directory |
| CVE-2026-62683 | 3.1 LOW | File Browser: Trailing-slash delete leaves a stale public share behind |
No comments yet