CVE-2026-61874

LOW

filebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete

Title source: cna
STIX 2.1

Description

filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the dormant public share URL.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-pp88-jhwj-5qh5)
https://github.com/filebrowser/filebrowser/security/advisories/GHSA-pp88-jhwj-5qh5
Third Party Advisory third-party-advisory
VulnCheck Advisory: filebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete
https://www.vulncheck.com/advisories/filebrowser-before-stale-public-share-via-trailing-slash-delete

Scores

CVSS v3 3.1
EPSS 0.0020
EPSS Percentile 9.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
filebrowser/filebrowser < 2.63.17
filebrowser/filebrowser 2.63.17
Published Jul 12, 2026
Tracked Since Jul 12, 2026