PT-2026-30906 · Unknown · Filebrowser

Kodareef5

·

Published

2026-04-07

·

Updated

2026-04-08

·

CVE-2026-35605

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions File Browser versions prior to 2.63.1
Description File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. The Matches() function in rules/rules.go uses strings.HasPrefix() without a trailing directory separator when matching paths against access rules. A rule for /uploads also matches /uploads backup/, potentially granting or denying access to unintended directories.
Recommendations Update to version 2.63.1 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-35605
GHSA-5Q48-Q4FM-G3M6

Affected Products

Filebrowser