Path Traversal Vulnerability in FileBrowser Quantum Web-Based File Manager by gtsteffaniak
CVE-2026-48777
9.3CRITICAL
What is CVE-2026-48777?
FileBrowser Quantum, a self-hosted web-based file manager, contains a path traversal vulnerability that allows unauthorized access to files outside of the designated shared directories. The issue arises through the handling of user-controlled request bodies, enabling attackers with a public share link set to AllowModify to manipulate, move, copy, or rename files. Importantly, this vulnerability affects certain versions prior to the patched releases, highlighting the significance of updating to versions 1.3.3-stable or 1.4.2-beta to mitigate the risk.
Affected Version(s)
filebrowser < 1.3.3-stable < 1.3.3-stable
filebrowser >= 1.4.0-beta, < 1.4.2-beta < 1.4.0-beta, 1.4.2-beta
