---
id: CVE-2026-54097
aliases:
  - GHSA-5ww9-jg6q-38r7
title: >-
  File Browser: Cross-user unauthorized share-link deletion via unbounded prefix
  match in DeleteWithPathPrefix
summary: >-
  File Browser: Cross-user unauthorized share-link deletion via unbounded prefix
  match in DeleteWithPathPrefix
severity: high
cwe:
  - CWE-639
vendor: filebrowser
product: github.com/filebrowser/filebrowser
ecosystem: go
affected:
  - github.com/filebrowser/filebrowser <= 1.11.0
  - github.com/filebrowser/filebrowser/v2 <= 2.63.5
patched:
  - github.com/filebrowser/filebrowser/v2 2.63.6
published: '2026-06-12'
updated: '2026-06-12'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-5ww9-jg6q-38r7'
references:
  - url: >-
      https://github.com/filebrowser/filebrowser/security/advisories/GHSA-5ww9-jg6q-38r7
  - url: >-
      https://github.com/filebrowser/filebrowser/commit/0231b7ebdfbe77a6c54027d30c4856c3fd81ee4d
  - url: 'https://github.com/filebrowser/filebrowser/releases/tag/v2.63.6'
  - url: 'https://github.com/advisories/GHSA-5ww9-jg6q-38r7'
tags:
  - ghsa
  - go
epss: 0.0045
epssPercentile: 0.38466
ingestedAt: '2026-07-07T15:41:58.988Z'
---

## Overview

### Summary
A low-privileged authenticated user of filebrowser (with `create` + `delete` permissions in their own isolated scope) can silently destroy share-link records belonging to any other user — including the administrator — by performing a legitimate DELETE on a file in their own directory whose logical path happens to be a byte-prefix of another user's stored `share.Link.Path`. The file contents of the victim are not exposed, but the victim's share links are irrevocably wiped.

### Details
`resourceDeleteHandler` in `http/resource.go` cleans up any share records that reference a deleted file by calling:

```go
// http/resource.go
err = d.store.Share.DeleteWithPathPrefix(file.Path)
```

`file.Path` here is the *logical* path from the URL of the deleting user's request (e.g. `/a`), not the absolute filesystem path. It is passed as-is to the bolt backend:

```go
// storage/bolt/share.go
func (s shareBackend) DeleteWithPathPrefix(pathPrefix string) error {
    var links []share.Link
    if err := s.db.Prefix("Path", pathPrefix, &links); err != nil {
        return err
    }
    for _, link := range links {
        err = errors.Join(err, s.db.DeleteStruct(&share.Link{Hash: link.Hash}))
    }
    return err
}
```
**Why the design contradicts this behavior.** `share.Link` carries a `UserID` field and the application elsewhere treats shares as per-user owned resources. `shareDeleteHandler` explicitly enforces `link.UserID != d.user.ID && !d.user.Perm.Admin → 403`. The file-deletion side-effect path is the only location that bypasses this rule.



### Impact
- Integrity: unauthorized deletion of share-link metadata belonging to arbitrary users, including administrators.
- Availability: effective denial-of-service of the share-link feature — a cooperating (or malicious) low-priv user can wipe the bulk of existing share links by iterating a short set of one- and two-character prefixes.

## Affected packages

- `github.com/filebrowser/filebrowser <= 1.11.0`
- `github.com/filebrowser/filebrowser/v2 <= 2.63.5`

## Remediation

Upgrade to a patched release:

- `github.com/filebrowser/filebrowser/v2 2.63.6`
