Executive brief
File Browser vulnerable to Stored Cross-site Scripting via text/template branding injection in github.com/filebrowser/filebrowser
Affected products
- Go github.com/filebrowser/filebrowser
- Go github.com/filebrowser/filebrowser/v2
Junglewise Threat Intelligence
CVE-2026-34530 · Severity: low · CVSS 3.1 · Published 2026-06-25
Technologies: github.com/filebrowser/filebrowser (Go), github.com/filebrowser/filebrowser/v2 (Go). Vendors: Go.
File Browser vulnerable to Stored Cross-site Scripting via text/template branding injection in github.com/filebrowser/filebrowser