FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled can delete arbitrary files outside the shared directory within the share owner’s configured storage scope. This affects public/api/resources and public/api/resources/bulk. This vulnerability is fixed in 1.3.1-stable and 1.3.9-beta.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fwj3-42wh-8673 | FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 14 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gtsteffaniak
Gtsteffaniak filebrowser |
|
| Vendors & Products |
Gtsteffaniak
Gtsteffaniak filebrowser |
Thu, 14 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled can delete arbitrary files outside the shared directory within the share owner’s configured storage scope. This affects public/api/resources and public/api/resources/bulk. This vulnerability is fixed in 1.3.1-stable and 1.3.9-beta. | |
| Title | FileBrowser Quantum: Unauthenticated Path Traversal in Public Share Delete Allows Arbitrary File Deletion | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T17:07:30.602Z
Reserved: 2026-05-06T19:38:10.567Z
Link: CVE-2026-44542
No data.
Status : Awaiting Analysis
Published: 2026-05-14T18:16:50.157
Modified: 2026-05-14T18:26:39.827
Link: CVE-2026-44542
No data.
OpenCVE Enrichment
Updated: 2026-05-14T18:45:26Z
Weaknesses
Github GHSA