Junglewise Threat Intelligence

CVE-2026-35606: GO-2026-5167 - File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check in github.com/filebrowser/filebrowser

CVE-2026-35606 · Severity: medium · CVSS 4 · Published 2026-06-25

Technologies: github.com/filebrowser/filebrowser (Go), github.com/filebrowser/filebrowser/v2 (Go). Vendors: Go.

Executive brief

File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check in github.com/filebrowser/filebrowser

Affected products

  • Go github.com/filebrowser/filebrowser
  • Go github.com/filebrowser/filebrowser/v2

Related threats