VulnSea

filebrowser vulnerabilities

CVEs whose affected-version data names the filebrowser package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-90929High· 8.1
1w ago

File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go)

File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler does not reject a tar…

Twilightfilebrowser · filebrowserEPSS 0.30%via NVD
CVE-2026-90927Medium· 6.5PoC
1w ago

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages…

Twilightfilebrowser · filebrowserEPSS 0.25%via NVD
CVE-2026-90930Medium· 6.8PoC
1w ago

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-de…

Twilightfilebrowser · filebrowserEPSS 0.41%via NVD
CVE-2026-90928Medium· 6.5PoC
1w ago

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request co…

Twilightfilebrowser · filebrowserEPSS 0.30%via NVD
filebrowser vulnerabilities (CVEs) · VulnSea