Executive brief
FileBrowser Quantum is a self-hosted web-based file manager. A security flaw in the public sharing feature allows anyone with a "modify" enabled share link to bypass directory restrictions. An attacker can use this to move, rename, or copy files they shouldn't have access to, potentially leading to the theft of sensitive data or the modification of critical system files within the owner's storage.
Technical details
A path traversal vulnerability exists in the `publicPatchHandler` within `backend/http/public.go`. The application uses `filepath.Join` (via `JoinPathAsUnix`) on user-provided `fromPath` and `toPath` fields before passing them to the `SanitizeUserPath` function. Because `filepath.Join` collapses '..' segments, the downstream sanitizer fails to detect the traversal, allowing the path to escape the intended share root. An unauthenticated attacker with a public share link where `AllowModify=true` can move, copy, or rename arbitrary files within the share owner's source root. This can be used to move sensitive files into the shared folder for download or overwrite existing files. The issue is fixed in versions 1.3.3-stable and 1.4.2-beta.
Affected products
- gtsteffaniak FileBrowser Quantum < 1.3.3-stable, < 1.4.2-beta
Timeline
- 2026-05-16: advisory: GitHub Security Advisory published
- 2026-05-18: patched: Version 1.3.3-stable released
- 2026-05-22: patched: Version 1.4.2-beta released
- 2026-06-16: disclosed: CVE-2026-48777 published