github.com/filebrowser/filebrowser vulnerabilities
CVEs whose affected-version data names the github.com/filebrowser/filebrowser package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
9 CVEsRSS
CVE-2026-54097HighFile Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
CVE-2026-54096HighFile Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
CVE-2026-54092High· 6.5File Browser has a DoS Vulnerability via Public Login API
File Browser has a DoS Vulnerability via Public Login API
CVE-2026-54094Medium· 6.8File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
CVE-2026-54093MediumFile Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
CVE-2026-54091High· 7.5File Browser has incorrect access control for public directory shares via rule path rebasing
File Browser has incorrect access control for public directory shares via rule path rebasing
CVE-2026-23849Medium· 5.3File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login
File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login
CVE-2025-53826HighFile Browser’s insecure JWT handling can lead to session replay attacks after logout
File Browser’s insecure JWT handling can lead to session replay attacks after logout
CVE-2025-52996Low· 3.1File Browser's password protection of links is bypassable
File Browser's password protection of links is bypassable