{"id":"CVE-2026-25890","aliases":["GHSA-4mh3-h929-w968","GO-2026-4474"],"title":"File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL","summary":"File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","vendor":"filebrowser","product":"github.com/filebrowser/filebrowser/v2","ecosystem":"go","affected":["github.com/filebrowser/filebrowser/v2 < 2.57.1"],"patched":["github.com/filebrowser/filebrowser/v2 2.57.1"],"published":"2026-02-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:34.233117663Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-4mh3-h929-w968","references":[{"url":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-4mh3-h929-w968"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25890"},{"url":"https://github.com/filebrowser/filebrowser/commit/489af403a19057f6b6b4b1dc0e48cbb26a202ef9"},{"url":"https://github.com/filebrowser/filebrowser"},{"url":"https://github.com/filebrowser/filebrowser/releases/tag/v2.57.1"}],"tags":["osv","go","exploit-available"],"epss":0.00469,"epssPercentile":0.39625,"exploits":{"github":1,"githubRepos":["https://github.com/mbanyamer/CVE-2026-25890-FileBrowser-Access-Control-Bypass"],"checkedAt":"2026-09-21T15:28:34.095Z"},"exploitAvailable":true,"ingestedAt":"2026-09-12T03:13:01.753Z","slug":"CVE-2026-25890","body":"## Overview\n\n### Summary\nAn authenticated user can bypass the application's \"Disallow\" file path rules by modifying the request URL. By adding multiple slashes (e.g., //private/) to the path, the authorization check fails to match the rule, while the underlying filesystem resolves the path correctly, granting unauthorized access to restricted files.\n\n### Details\nThe vulnerability allows users to bypass \"Disallow\" rules defined by administrators.\n\nThe issue stems from how the application handles URL path normalization and rule matching:\n\n1. Router Configuration: The router in `http/http.go` is configured with `r.SkipClean(true)`. This prevents the automatic collapse of multiple slashes (e.g., // becoming /) before the request reaches the handler.\n2. Insecure Rule Matching: The rule enforcement logic in `rules/rules.go` relies on a simple string prefix match: `strings.HasPrefix(path, r.Path)`. If a rule disallows /private, a request for //private fails this check because //private does not strictly start with /private.\n3. Filesystem Resolution: After bypassing the rule check, the non-normalized path is passed to the filesystem. The filesystem treats the multiple slashes as a single separator, successfully resolving //private/secret.txt and serving the file.\n\n### PoC\n[Python minimal PoC](https://github.com/user-attachments/files/24823114/poc.py)\n\nThe following steps demonstrate the vulnerability:\n1. Setup:\n  - Admin user creates a folder /private and adds a file /private/secret.txt.\n<img width=\"971\" height=\"719\" alt=\"Screenshot_20260123_151608\" src=\"https://github.com/user-attachments/assets/2071c92e-2bbe-46f8-a338-05b0f53d381a\" />\n<img width=\"890\" height=\"386\" alt=\"Screenshot_20260123_151551\" src=\"https://github.com/user-attachments/assets/1def540a-de26-4666-a6ab-058d5927bfbe\" />\n  - Admin adds a Disallow rule for user bob on the path /private.\n<img width=\"1005\" height=\"1126\" alt=\"Screenshot_20260123_151502\" src=\"https://github.com/user-attachments/assets/e9b57d59-f4ab-41d8-b056-8ffdaa219963\" />\n\n2. Verification:\n  - User bob requests GET /api/resources/private/secret.txt.\n  - Server responds: 403 Forbidden.\n<img width=\"1193\" height=\"721\" alt=\"Screenshot_20260123_154446\" src=\"https://github.com/user-attachments/assets/dd092a10-2f8c-4a3c-b48f-d540c483bb5a\" />\n3. Exploit:\n  - User bob requests GET /api/resources//private/secret.txt.\n  - Server responds: 200 OK (Bypass successful).\n<img width=\"1193\" height=\"721\" alt=\"Screenshot_20260123_154544\" src=\"https://github.com/user-attachments/assets/27ebb82c-f7c2-467d-ae82-f495ae3aa2d4\" />\n<img width=\"1196\" height=\"818\" alt=\"Screenshot_20260123_154618\" src=\"https://github.com/user-attachments/assets/82035884-9a24-490d-b928-7bdd2dbe3193\" />\n\n\n### Impact\nThis vulnerability impacts the confidentiality and integrity of data stored in filebrowser.\n- Confidentiality: Users can read files they are explicitly forbidden from accessing.\n- Integrity: If the user has general write permissions but is restricted from specific directories via rules, they can bypass these restrictions to rename, delete, or modify files.\n\n## Affected packages\n\n- `github.com/filebrowser/filebrowser/v2 < 2.57.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/filebrowser/filebrowser/v2 2.57.1`","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}