Security Advisories for github.com/filebrowser/filebrowser in go
High
1 day ago
File Browser has incorrect access control for public directory shares via rule path rebasing
go
github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
Moderate
1 day ago
File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
go
github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
Moderate
1 day ago
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
go
github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
High
1 day ago
File Browser has a DoS Vulnerability via Public Login API
go
github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
High
1 day ago
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
go
github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
High
1 day ago
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
go
github.com/filebrowser/filebrowser/v2, github.com/filebrowser/filebrowser
Moderate
5 months ago
File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login
go
github.com/filebrowser/filebrowser/v2, github.com/filebrowser/filebrowser
High
11 months ago
File Browser’s insecure JWT handling can lead to session replay attacks after logout
go
github.com/filebrowser/filebrowser
Moderate
12 months ago
File Browser vulnerable to insecure password handling
go
github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
Low
12 months ago
File Browser's password protection of links is bypassable
go
github.com/filebrowser/filebrowser
High
12 months ago
File Browser vulnerable to command execution allowlist bypass
go
github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
Moderate
12 months ago
File Browser allows sensitive data to be transferred in URL
go
github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
High
12 months ago
filebrowser allows Stored Cross-Site Scripting through the Markdown preview function
go
github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
Moderate
12 months ago
filebrowser Sets Insecure File Permissions
go
github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2