FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.
References
| Link | Resource |
|---|---|
| https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.2.2-stable | Release Notes |
| https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.1-beta | Release Notes |
| https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-525j-95gf-766f | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-03-10 18:18
Updated : 2026-03-18 17:13
NVD link : CVE-2026-30933
Mitre link : CVE-2026-30933
CVE.ORG link : CVE-2026-30933
JSON object : View
Products Affected
filebrowser
- filebrowser
