Executive brief
FileRise, a self-hosted file management and storage platform, is vulnerable to a security flaw that allows unauthorized users to overwrite critical system files. By using a specially crafted file upload request, an attacker can bypass security checks to overwrite the administrator account database. This can lead to a complete takeover of the system and, in some cases, allow the attacker to execute malicious code on the server.
Technical details
A path traversal vulnerability exists in the `/api/folder/uploadToSharedFolder.php` endpoint of FileRise. The `FolderController` validates filenames using `basename()` and a regex that fails to account for URL-encoded characters (e.g., `%2f`). When `UploadModel::handleUpload` subsequently calls `urldecode()`, path separators are re-introduced (e.g., `..%2f` becomes `../`), allowing files to be written outside the intended directory. Because `UploadNamePolicy::isAllowedForWrite()` only checks the final component of the path, the traversal sequence bypasses extension policies. An attacker with a valid shared-folder token can overwrite `users/users.txt` to create an admin account, leading to full application compromise and potential RCE. This is fixed in version 3.16.0 by decoding filenames before validation.
Affected products
- error311 FileRise before 3.16.0
Timeline
- 2026-06-17: patched: Version 3.16.0 released
- 2026-06-19: disclosed: CVE-2026-54414 published