Executive brief
File Browser is a file management system that allows authenticated users to access files within configured scope boundaries. The application applies access rules to the path that users request, but fails to reapply those rules after resolving symbolic links to their actual targets. An authenticated user can bypass file access restrictions by accessing denied files through symbolic link aliases that point to restricted areas, enabling unauthorized reading and modification of protected files.
Technical details
This is a path traversal vulnerability (CWE-59) in symbolic link resolution. File Browser's authorization layer (CheckRules in http/data.go) applies deny rules to the lexical path requested by the user using regex or prefix matching, but the ScopedFs filesystem layer later resolves symbolic links to their actual targets without reapplying the deny rules. An authenticated non-administrator can read or overwrite files in rule-denied paths if those files are reachable through an in-scope symbolic link alias—both the link and target must remain within the user's assigned scope. The vulnerability requires the existence of a symbolic link pointing to denied content (typically created out-of-band by an administrator, or present in mounted volumes or restored backups), and the attacker must possess Download or Modify permissions. The project is unmaintained and no patch will be released.
Affected products
- File Browser File Browser through 2.63.23
Timeline
- 2026-08-31: disclosed
- 2026-09-14: advisory