Executive brief
FileBrowser Quantum is a self-hosted web application used for managing files remotely. A security flaw in how the application handles subtitle files allows any logged-in user to bypass folder restrictions and read sensitive files on the host server. This could lead to the exposure of system passwords, SSH keys, and database credentials, potentially allowing an attacker to take full control of the server.
Technical details
A path traversal vulnerability exists in the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) of FileBrowser Quantum. The endpoint processes two query parameters, `path` and `name`, without proper sanitization. The `path` parameter is passed directly to `idx.GetRealPath()` without the standard `SanitizeUserPath()` check, allowing an attacker to escape the storage root. The `name` parameter is joined using `filepath.Join()` without stripping directory components, providing a second traversal vector. An authenticated attacker, regardless of their specific permissions or scope restrictions, can exploit these vectors to read any UTF-8 encoded file under 50MB that the server process has permission to access, such as `/etc/passwd` or JWT signing keys. The issue is fixed in version 1.4.3-beta.
Affected products
- gtsteffaniak FileBrowser Quantum < 1.4.3-beta
Timeline
- 2026-06-08: patched: Fix committed to repository
- 2026-06-10: advisory: GitHub Security Advisory published
- 2026-07-20: disclosed: CVE published to NVD