216.73.216.233

CVE-2026-48777

· Published 16/06/2026 22:16 · Modified 16/06/2026 20:45 · Author: The MITRE Corporation

Labels: CVE-2026-48777 2026-06-16CVE-2026-48777CWE-22[email protected]

Essential information

Published
16/06/2026 22:16
Modified
16/06/2026 20:45
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CWE-22
CVSS vector

CVSS metrics

Description

FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go which joins user-controlled fromPath and toPath body fields with the trusted d.share.Path BEFORE the downstream sanitizer runs. Because filepath.Join collapses .. segments during the join, the sanitizer in resourcePatchHandler never sees the traversal and the move/copy/rename operates on a path outside the shared directory. The same root-cause pattern was patched for the bulk DELETE endpoint as CVE-2026-44542 (GHSA-fwj3-42wh-8673), but the PATCH handler with the identical pattern was not updated. A public share link with AllowModify=true is sufficient to exploit this. Anyone holding such a link can move, copy, or rename arbitrary files within the share owner's source root. This issue has been fixed in versions 1.3.3-stable and 1.4.2-beta.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
filebrowser quantum / filebrowser quantum cpe:2.3:a:filebrowser_quantum:filebrowser_quantum:<1.3.3-stable>*:*:*:*:*:*:*
filebrowser quantum / filebrowser quantum cpe:2.3:a:filebrowser_quantum:filebrowser_quantum:<1.4.2-beta>*:*:*:*:*:*:*

References