Executive brief
File Browser, a web-based file management utility, contains a flaw in how it assigns storage folders to new users. When self-registration is enabled, the system simplifies usernames to create folder names (for example, turning 'user/one' and 'user-one' into the same folder). This allows a malicious actor to register a specific username that grants them full access to another user's private files, leading to data theft or unauthorized file modification.
Technical details
The vulnerability exists in the `cleanUsername()` function within `settings/dir.go`, which performs a many-to-one normalization of usernames by stripping '..' and replacing non-alphanumeric characters with dashes. When `Signup` and `CreateUserDir` are enabled, File Browser fails to verify if the resulting normalized 'scope' (home directory) is already assigned to an existing user. An attacker can register a username that normalizes to a victim's existing scope (e.g., 'alice/' colliding with 'alice'), gaining full read/write access to the victim's files. The issue is addressed in version 2.63.17.
Affected products
- File Browser filebrowser/filebrowser/v2 <= 2.63.16
Timeline
- 2026-07-04: advisory: Initial GitHub Advisory published
- 2026-07-20: disclosed: Full advisory disclosure and timeline update