Description
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.
Problem types
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CWE-306: Missing Authentication for Critical Function
CWE-602: Client-Side Enforcement of Server-Side Security
Product status
>= 1.2.6-beta, < 1.2.2-stable
= 1.1.3-stable
References
github.com/...rowser/security/advisories/GHSA-525j-95gf-766f
github.com/...ffaniak/filebrowser/releases/tag/v1.2.2-stable
github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.1-beta