FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/<hash> without context-aware escaping. The server uses text/template instead of html/template, allowing injected scripts to execute when victims visit the share URL. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.
References
| Link | Resource |
|---|---|
| https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.2.2-stable | Release Notes |
| https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.1-beta | Release Notes |
| https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-r633-fcgp-m532 | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Mar 2026, 16:52
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Filebrowser
Filebrowser filebrowser |
|
| Summary |
|
|
| CPE | cpe:2.3:a:filebrowser:filebrowser:1.2.1:stable:*:*:*:*:*:* cpe:2.3:a:filebrowser:filebrowser:1.3.0:beta:*:*:*:*:*:* cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* |
|
| References | () https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.2.2-stable - Release Notes | |
| References | () https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.1-beta - Release Notes | |
| References | () https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-r633-fcgp-m532 - Exploit, Vendor Advisory |
10 Mar 2026, 18:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-10 18:18
Updated : 2026-03-18 16:52
NVD link : CVE-2026-30934
Mitre link : CVE-2026-30934
CVE.ORG link : CVE-2026-30934
JSON object : View
Products Affected
filebrowser
- filebrowser
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
