Executive brief
File Browser, a web-based file management interface, contains a security flaw that allows users to access files outside of their assigned folders. By using symbolic links (shortcuts), a restricted user or even an unauthenticated person with a shared link can bypass security boundaries to read or overwrite sensitive system files. This could lead to the exposure of private data or the corruption of critical files on the server hosting the application.
Technical details
File Browser uses 'afero.NewBasePathFs' to enforce user scopes, which prevents lexical path traversal (e.g., using '../') but does not stop the underlying filesystem from resolving symbolic links. The vulnerability manifests in two variants: direct symlinks to out-of-scope files and files accessed through a symlinked parent directory. Because the application's metadata layer and HTTP handlers (including raw, resource, TUS upload, and share handlers) do not consistently validate the resolved target path against the user's scope, attackers can perform unauthorized read and write operations. This affects various API endpoints such as /api/raw/, /api/resources/, and /api/tus/. The issue is resolved in version 2.63.14.
Affected products
- filebrowser File Browser < 2.63.14
Timeline
- 2026-06-03: advisory: GitHub security advisory published
- 2026-06-25: disclosed: NVD publication date
- 2026-06-25: patched: Fix confirmed in version 2.63.14