GHSA-8jx5-5rq8-69m2HighCVSS 6.8

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules,...

Published
August 14, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (1)

📋 Description

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with alternate path representations that match no rule but resolve to the same filesystem object, gaining unauthorized access to denied files within their scope.

🔗 References (4)