Out-of-Scope File Deletion Vulnerability in Filebrowser by Filebrowser
CVE-2026-73613
7.2HIGH
What is CVE-2026-73613?
Filebrowser versions prior to 2.63.19 are vulnerable to an out-of-scope file deletion due to flaws in the TUS upload cache eviction mechanism. This vulnerability enables authenticated users, having only Create permissions, to delete arbitrary files that fall outside their authorized scope. By exploiting this flaw, an attacker can create a symlink that swaps an ancestor directory during the cache's time-to-live (TTL) window, thereby bypassing the ScopedFs scope guards and the necessary Perm.Delete checks. This results in the potential compromise of sensitive files, posing significant security risks.
Affected Version(s)
filebrowser 0 < 2.63.19
filebrowser 2.63.19
