Executive brief
File Browser is a web-based file management interface used to browse and manage files on a server. An authenticated user with limited permissions (upload and modify only, but not delete) can bypass authorization controls to permanently delete entire directory trees, including files protected by access rules. This allows accounts deliberately restricted to upload-only access to destroy arbitrary data within their assigned scope.
Technical details
The vulnerability is an incorrect authorization flaw (CWE-863) in the direct-upload endpoint (resourcePostHandler in http/resource.go). When a POST request with ?override=true targets an existing directory, the handler fails to reject it (unlike the TUS upload handler). The writeFile function then fails to open a directory for writing, triggering a failure-cleanup path that calls Fs.RemoveAll on the request path, recursively deleting the entire tree. This cleanup bypasses both the Perm.Delete permission check and the checkDescendants rule walk that the delete and patch handlers enforce. An authenticated attacker with only default Create and Modify permissions can exploit this to delete any directory within their scope. The vulnerability was introduced in v2.5.0 and remains unfixed; the project is no longer maintained and no patch will ship.
Affected products
- File Browser File Browser 2.5.0 to 2.63.23
Timeline
- 2026-09-14: disclosed
- 2026-08-31: advisory: GitHub Security Advisory GHSA-c4fr-5f24-4wrj published