CVE-2026-82236
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.
Zwakheid
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.
Bronnen
- https://github.com/filebrowser/filebrowser/commit/0231b7eb
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-r6pg-pg54-rcr5
- https://www.vulncheck.com/advisories/file-browser-2.63.6-through-2.63.23-share-link-exposure-via-file-deletion
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-r6pg-pg54-rcr5
Vind de bug voordat een aanvaller dat doet.
Log in met GitHub en start je eerste audit binnen een minuut. Voor het gratis abonnement is geen creditcard nodig.