Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

filebrowser — Vulnerabilities & Security Advisories 53

Browse all 53 CVE security advisories affecting filebrowser. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Filebrowser is an open-source web application designed to manage files and folders within a web interface, primarily serving as a lightweight alternative to traditional FTP servers for self-hosted environments. Its architecture, built on Go, facilitates easy deployment but has historically exposed users to significant security risks. Analysis of its twenty-eight recorded Common Vulnerabilities and Exposures reveals a pattern of critical flaws, predominantly involving remote code execution and cross-site scripting. These vulnerabilities often stem from insufficient input validation and improper access controls, allowing attackers to escalate privileges or execute arbitrary commands on the host system. While the project maintains an active development cycle, past incidents highlight the dangers of complex file manipulation logic. Users are advised to implement strict network segmentation and regular patching to mitigate the inherent risks associated with exposing file system operations through a web interface.

Top products by filebrowser: filebrowser
CVE ID Title CVSS Severity Published
CVE-2026-62684 File Browser: Share API exposes the password hash and bypass token — filebrowser CWE-200 2.7 Low 2026-08-18
CVE-2026-72838 FileBrowser before 2.63.19 Disk Exhaustion via TUS Upload — filebrowser CWE-770 6.5 Medium 2026-08-14
CVE-2026-72837 File Browser before 2.63.20 Privilege Escalation via Proxy Authentication — filebrowser CWE-284 8.8 High 2026-08-14
CVE-2026-72835 filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization — filebrowser CWE-41 6.8 Medium 2026-08-14
CVE-2026-72836 FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass — filebrowser CWE-178 8.1 High 2026-08-14
CVE-2026-72834 filebrowser before 2.63.19 Permission Bypass via checksum — filebrowser CWE-200 4.3 Medium 2026-08-14
CVE-2026-72839 filebrowser through 2.63.16 Privilege Escalation via Signup — filebrowser CWE-266 9.8 Critical 2026-08-13
CVE-2026-73613 filebrowser before 2.63.19 Out-of-Scope File Deletion via Symlink — filebrowser CWE-59 8.2 High 2026-08-13
CVE-2026-73612 File Browser before v2.63.22 Authorization Bypass via Recursive Operations — filebrowser CWE-639 8.1 High 2026-08-13
CVE-2026-73611 File Browser 2.50.0 through 2.63.21 JWT Expiration Bypass — filebrowser CWE-613 6.8 Medium 2026-08-13
CVE-2026-62685 File Browser: Colliding username normalization gives two users the same home directory — filebrowser CWE-647 8.1 High 2026-07-15
CVE-2026-62843 File Browser: Archive builder turns backslash filenames into path traversal (zip-slip) — filebrowser CWE-22 6.8 Medium 2026-07-15
CVE-2026-62683 File Browser: Trailing-slash delete leaves a stale public share behind — filebrowser CWE-863 3.1 Low 2026-07-15
CVE-2026-61874 filebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete — filebrowser CWE-863 3.1 Low 2026-07-12
CVE-2026-55668 File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope — filebrowser CWE-22 6.3 Medium 2026-07-08
CVE-2026-54090 File Browser: Command Allowlist Bypass via Shell Metacharacter Injection — filebrowser CWE-77 - - 2026-06-25
CVE-2026-54088 File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE) — filebrowser CWE-78 - - 2026-06-25
CVE-2026-54089 File Browser: Authentication Bypass via Proxy Auth Header Forgery — filebrowser CWE-287 9.1 Critical 2026-06-25
CVE-2026-54091 File Browser: Incorrect access control in public directory shares via rule path rebasing — filebrowser CWE-863 7.5 High 2026-06-25
CVE-2026-54092 File Browser: DoS Vulnerability on Public Login API — filebrowser CWE-1284 6.5 Medium 2026-06-25
CVE-2026-54097 File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix — filebrowser CWE-639 - - 2026-06-25
CVE-2026-54093 File Browser: Path traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames — filebrowser CWE-22 - - 2026-06-25
CVE-2026-54094 File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope — filebrowser CWE-22 7.5 High 2026-06-25
CVE-2026-54096 File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path — filebrowser CWE-863 8.4 High 2026-06-25
CVE-2026-55667 File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup — filebrowser CWE-22 8.2 High 2026-06-25
CVE-2026-35607 File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands — filebrowser CWE-269 8.1 High 2026-04-07
CVE-2026-35606 File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check — filebrowser CWE-862 6.5AI Medium AI 2026-04-07
CVE-2026-35605 File Browser has an access rule bypass via HasPrefix without trailing separator in path matching — filebrowser CWE-22 7.3AI High AI 2026-04-07
CVE-2026-35604 File Browser share links remain accessible after Share/Download permissions are revoked — filebrowser CWE-863 4.3AI Medium AI 2026-04-07
CVE-2026-35585 File Browser has a Command Injection via Hook Runner — filebrowser CWE-78 8.8AI High AI 2026-04-07

This page lists every published CVE security advisory associated with filebrowser. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.