Executive brief
File Browser, a web-based file management interface, contains a flaw where deleting a folder using a path with a trailing slash (e.g., "/folder/") fails to remove its associated public sharing link. This results in a "stale" share remaining in the system's database even after the original files are gone. If a user later creates a new folder with the same name, the old public link will automatically become active again, potentially exposing new, private files to anyone who has the original sharing URL.
Technical details
A vulnerability exists in File Browser's Bolt backend where the `DeleteWithPathPrefix` function performs database queries using unnormalized paths. When a directory is deleted via a path containing a trailing slash (e.g., `/a/`), the database prefix query fails to match the exact stored share path (e.g., `/a`), though it may match descendants. Consequently, the directory is removed from the filesystem, but the public share record persists in the database. If a directory is later recreated at the same path, the stale share record becomes active, allowing unauthenticated access to the new content via the original share hash. This issue is resolved in version 2.63.17 by normalizing paths before the prefix query.
Affected products
- filebrowser File Browser < 2.63.17
Timeline
- 2026-06-27: patched: Version 2.63.17 released
- 2026-06-28: advisory: GitHub Security Advisory published
- 2026-07-15: disclosed: CVE published to NVD