Executive brief
FileBrowser Quantum is a self-hosted web application used for managing and sharing files. A security flaw allows unauthorized individuals who have access to a public file-sharing link (with delete permissions enabled) to delete files they should not have access to. By manipulating the web request, an attacker can bypass folder restrictions and delete any file within the storage area of the person who created the share, potentially leading to significant data loss.
Technical details
A path traversal vulnerability exists in FileBrowser Quantum's public API endpoints due to improper input sanitization. Specifically, in the 'public/api/resources' and 'public/api/resources/bulk' endpoints, attacker-controlled path input is joined with a trusted base path before the 'SanitizeUserPath()' function is called. This allows an unauthenticated attacker who possesses a valid public share hash (with delete permissions enabled) to use traversal sequences like '../' to escape the intended directory. An attacker can then delete any file within the storage scope of the user who created the share. The issue is fixed in versions 1.3.1-stable and 1.3.9-beta.
Affected products
- gtsteffaniak FileBrowser Quantum < 1.3.1-stable, < 1.3.9-beta
Timeline
- 2026-05-01: advisory: GitHub Security Advisory published by maintainer
- 2026-05-14: disclosed: CVE published to NVD