File Browser 2.63.23 及更早版本对请求的字典路径应用了路径规则,但在解析符号链接时未重新对目标路径应用规则,这使得经过身份验证的用户可以绕过“禁止”规则。攻击者可以通过作用域内的符号链接别名访问被禁止的路径,从而读取或覆盖被规则拒绝的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| filebrowser | filebrowser | 0 ~ 2.63.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90929 | 8.1 HIGH | File Browser 2.5.0 Directory Deletion via Upload Failure Cleanup |
| CVE-2026-90927 | 6.5 MEDIUM | filebrowser through 2.63.23 Denial of Service via unbounded WebSocket message |
| CVE-2026-90928 | 6.5 MEDIUM | File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint |
No comments yet