Directory Traversal Vulnerability in File Browser by File Browser Inc.
CVE-2026-28492
7.1HIGH
What is CVE-2026-28492?
A directory traversal vulnerability exists in File Browser versions prior to 2.61.0, allowing unauthorized users to access and download files from directories beyond the intended shared folder. This issue arises when creating public share links; the middleware responsible for defining the filesystem root incorrectly points to the parent directory rather than the shared directory, which could expose sensitive files. The vulnerability has been resolved in version 2.61.0.
Affected Version(s)
filebrowser < 2.61.0
