Junglewise Threat Intelligence

CVE-2026-62685: File Browser directory traversal and isolation bypass via username normalization collision

CVE-2026-62685 · Severity: high · CVSS 8.1 · Published 2026-07-15

Technologies: File Browser, github.com/filebrowser/filebrowser (Go), github.com/filebrowser/filebrowser/v2 (Go). Vendors: File Browser, Go.

Executive brief

File Browser, a web-based file management utility, contains a flaw in how it assigns storage folders to new users. When self-registration is enabled, the system simplifies usernames to create folder names (for example, turning 'user/one' and 'user-one' into the same folder). This allows a malicious actor to register a specific username that grants them full access to another user's private files, leading to data theft or unauthorized file modification.

Technical details

The vulnerability exists in the `cleanUsername()` function within `settings/dir.go`, which performs a many-to-one normalization of usernames by stripping '..' and replacing non-alphanumeric characters with dashes. When `Signup` and `CreateUserDir` are enabled, File Browser fails to verify if the resulting normalized 'scope' (home directory) is already assigned to an existing user. An attacker can register a username that normalizes to a victim's existing scope (e.g., 'alice/' colliding with 'alice'), gaining full read/write access to the victim's files. The issue is addressed in version 2.63.17.

Affected products

  • File Browser filebrowser/filebrowser/v2 <= 2.63.16

Timeline

  • 2026-07-04: advisory: Initial GitHub Advisory published
  • 2026-07-20: disclosed: Full advisory disclosure and timeline update

References

Related threats