FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.
References
| Link | Resource |
|---|---|
| https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.2.2-stable | Release Notes |
| https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.1-beta | Release Notes |
| https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-525j-95gf-766f | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Mar 2026, 17:13
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Filebrowser
Filebrowser filebrowser |
|
| Summary |
|
|
| CPE | cpe:2.3:a:filebrowser:filebrowser:1.2.1:stable:*:*:*:*:*:* cpe:2.3:a:filebrowser:filebrowser:1.3.0:beta:*:*:*:*:*:* cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* |
|
| References | () https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.2.2-stable - Release Notes | |
| References | () https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.1-beta - Release Notes | |
| References | () https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-525j-95gf-766f - Exploit, Vendor Advisory |
10 Mar 2026, 18:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-10 18:18
Updated : 2026-03-18 17:13
NVD link : CVE-2026-30933
Mitre link : CVE-2026-30933
CVE.ORG link : CVE-2026-30933
JSON object : View
Products Affected
filebrowser
- filebrowser
