filebrowser
8 known vulnerabilities in filebrowser, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-90930 CVSS 7.6 high File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the…
- CVE-2026-90929 CVSS 7.2 high File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler…
- CVE-2026-90928 CVSS 7.1 high File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle…
- CVE-2026-90927 CVSS 7.1 high filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing…
- CVE-2026-82238 CVSS 2.3 low filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the…
- CVE-2026-82237 CVSS 2.3 low filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share…
- CVE-2026-82236 CVSS 2.3 low File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared…
- CVE-2026-82235 CVSS 8.2 high filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger…