Directory Traversal Vulnerability in File Browser by File Browser Inc.
CVE-2026-28492

7.1HIGH

Key Information:

Vendor
CVE Published:
5 March 2026

What is CVE-2026-28492?

A directory traversal vulnerability exists in File Browser versions prior to 2.61.0, allowing unauthorized users to access and download files from directories beyond the intended shared folder. This issue arises when creating public share links; the middleware responsible for defining the filesystem root incorrectly points to the parent directory rather than the shared directory, which could expose sensitive files. The vulnerability has been resolved in version 2.61.0.

Affected Version(s)

filebrowser < 2.61.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.