Directory Traversal Vulnerability in FileBrowser Quantum by GT Steffaniak
CVE-2026-44542
9.1CRITICAL
What is CVE-2026-44542?
FileBrowser Quantum, a self-hosted web-based file manager, is susceptible to a directory traversal vulnerability. Attackers can manipulate path input, which is improperly joined with a trusted base path before sanitization. This flaw allows unauthorized access to files outside the intended directory, potentially deleting arbitrary files if the attacker possesses a valid public share hash with delete permissions. Affected endpoints include public/api/resources and public/api/resources/bulk. This vulnerability has been addressed in versions 1.3.1-stable and 1.3.9-beta.
Affected Version(s)
filebrowser < 1.3.1-stable < 1.3.1-stable
filebrowser < 1.3.9-beta < 1.3.9-beta
