CVE-2026-54910: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in gtsteffaniak filebrowser
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors. The primary vector is the `path` parameter: it is passed directly to `idx.GetRealPath()` without calling `SanitizeUserPath()`, allowing an attacker to escape the storage root and set `parentDir` to any directory on the host. No existing anchor file is required. The secondary vector is the `name` parameter: it is joined with `parentDir` via `filepath.Join(parentDir, name)` without stripping directory components, allowing traversal relative to any resolved `parentDir`. Any authenticated user (regardless of role or permissions) can exploit either vector to read any text file readable by the server process, including `/etc/passwd`, SSH keys, database credentials, and JWT signing keys. Version 1.4.3-beta patches the issue.
AI Analysis
Technical Summary
CVE-2026-54910 describes a path traversal vulnerability in FileBrowser Quantum's subtitlesHandler endpoint (GET /api/media/subtitles) prior to version 1.4.3-beta. The 'path' parameter is passed unsanitized to idx.GetRealPath(), allowing attackers to escape the storage root directory without requiring an anchor file. The 'name' parameter is joined with the resolved parent directory without stripping directory components, enabling further traversal. Any authenticated user can exploit these vectors to read any text file accessible by the server process, including sensitive system and application files. The vulnerability is patched in version 1.4.3-beta.
Potential Impact
An attacker with any authenticated access can exploit this vulnerability to read arbitrary text files on the server, potentially exposing sensitive information such as system user data (/etc/passwd), SSH private keys, database credentials, and JWT signing keys. This compromises confidentiality but does not affect integrity or availability. The vulnerability has a CVSS 3.1 score of 7.7 (high severity) with network attack vector, low attack complexity, and no user interaction required.
Mitigation Recommendations
Version 1.4.3-beta of FileBrowser Quantum patches this vulnerability. Users should upgrade to version 1.4.3-beta or later to remediate this issue. No official patch or remediation level is explicitly stated beyond this version update. Until upgraded, restrict authenticated user access to trusted parties only.
CVE-2026-54910: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in gtsteffaniak filebrowser
Description
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors. The primary vector is the `path` parameter: it is passed directly to `idx.GetRealPath()` without calling `SanitizeUserPath()`, allowing an attacker to escape the storage root and set `parentDir` to any directory on the host. No existing anchor file is required. The secondary vector is the `name` parameter: it is joined with `parentDir` via `filepath.Join(parentDir, name)` without stripping directory components, allowing traversal relative to any resolved `parentDir`. Any authenticated user (regardless of role or permissions) can exploit either vector to read any text file readable by the server process, including `/etc/passwd`, SSH keys, database credentials, and JWT signing keys. Version 1.4.3-beta patches the issue.
CVSS v3.1
Score 7.7high
Affected software
pkg:github/gtsteffaniak/filebrowserRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-54910 describes a path traversal vulnerability in FileBrowser Quantum's subtitlesHandler endpoint (GET /api/media/subtitles) prior to version 1.4.3-beta. The 'path' parameter is passed unsanitized to idx.GetRealPath(), allowing attackers to escape the storage root directory without requiring an anchor file. The 'name' parameter is joined with the resolved parent directory without stripping directory components, enabling further traversal. Any authenticated user can exploit these vectors to read any text file accessible by the server process, including sensitive system and application files. The vulnerability is patched in version 1.4.3-beta.
Potential Impact
An attacker with any authenticated access can exploit this vulnerability to read arbitrary text files on the server, potentially exposing sensitive information such as system user data (/etc/passwd), SSH private keys, database credentials, and JWT signing keys. This compromises confidentiality but does not affect integrity or availability. The vulnerability has a CVSS 3.1 score of 7.7 (high severity) with network attack vector, low attack complexity, and no user interaction required.
Mitigation Recommendations
Version 1.4.3-beta of FileBrowser Quantum patches this vulnerability. Users should upgrade to version 1.4.3-beta or later to remediate this issue. No official patch or remediation level is explicitly stated beyond this version update. Until upgraded, restrict authenticated user access to trusted parties only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T13:49:33.556Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5e33e12a4a8d598937d232
Added to database: 07/20/2026, 14:42:41 UTC
Last enriched: 07/20/2026, 14:56:41 UTC
Last updated: 07/21/2026, 03:42:28 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.