PT-2026-22992 · Unknown · Filebrowser

Uug4Na

·

Published

2026-03-02

·

Updated

2026-05-07

·

CVE-2026-28492

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions File Browser versions prior to 2.61.0
Description File Browser provides a file managing interface. A directory traversal issue exists in public share links prior to version 2.61.0. The withHashFile middleware in http/public.go incorrectly uses filepath.Dir(link.Path) to determine the filesystem root for shared directories. This allows anyone with a share link to access files in sibling directories, leading to unauthenticated information disclosure. The issue affects both directory listing via /api/public/share/{hash} and file download via /api/public/dl/{hash}/path. The root cause is that the filesystem root is set to the parent directory instead of the shared directory itself. This allows access to files outside the intended shared directory.
Recommendations Update File Browser to version 2.61.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28492
GHSA-MR74-928F-RW69
GO-2026-4585
SUSE-SU-2026:1042-1

Affected Products

Filebrowser