Executive brief
File Browser, a web-based file management utility, contains a flaw that can lead to unintended data exposure. When a user deletes a folder that was previously shared publicly, the system may fail to deactivate the public sharing link if the deletion request includes a trailing slash. If a folder with the same name is created later, the old public link becomes active again, potentially exposing new, private files to anyone who has the original link.
Technical details
A vulnerability exists in filebrowser's Bolt storage backend where the `DeleteWithPathPrefix` function fails to normalize paths before performing a database prefix query. When an authenticated user deletes a directory using a path with a trailing slash (e.g., '/a/'), the database query for the share index misses the exact share record (e.g., '/a'). Consequently, the directory is deleted but the public share metadata remains in the database. If a directory is later recreated at the same path, the dormant public share becomes active, exposing the new directory's contents to unauthenticated users via the original share hash. This issue is fixed in version 2.63.17 by ensuring paths are normalized before the index query.
Affected products
- filebrowser filebrowser < 2.63.17
Timeline
- 2026-06-28: advisory: GitHub Security Advisory published
- 2026-07-12: disclosed: NVD publication date