Executive brief
FileBrowser Quantum, a self-hosted web-based file management system, contains a vulnerability that allows unauthorized users to view sensitive system information. An attacker could gain access to internal file paths and source details without needing to log in. This exposure could help an attacker map out the server's internal structure for further exploitation.
Technical details
FileBrowser Quantum prior to versions 1.3.2-stable and 1.4.1-beta contains an information disclosure vulnerability (CWE-200). The flaw allows an unauthenticated remote attacker to access sensitive metadata, specifically internal file system paths and source information. This occurs due to insufficient access controls on certain information-sharing components. Attackers can exploit this over the network without user interaction to facilitate reconnaissance. The issue is resolved in versions 1.3.2-stable and 1.4.1-beta.
Affected products
- gtsteffaniak FileBrowser Quantum < 1.3.2-stable, < 1.4.1-beta
Timeline
- 2026-05-14: advisory: GitHub Security Advisory published
- 2026-07-20: disclosed: CVE published to NVD