Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-67cg-cpj7-qgc9 | File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check |
Thu, 16 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 09 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Filebrowser
Filebrowser filebrowser |
|
| Vendors & Products |
Filebrowser
Filebrowser filebrowser |
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resourceGetHandler in http/resource.go returns full text file content without checking the Perm.Download permission flag. All three other content-serving endpoints (/api/raw, /api/preview, /api/subtitle) correctly verify this permission before serving content. A user with download: false can read any text file within their scope through two bypass paths. This vulnerability is fixed in 2.63.1. | |
| Title | File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-09T16:18:22.881Z
Reserved: 2026-04-03T21:25:12.162Z
Link: CVE-2026-35606
Updated: 2026-04-09T15:15:19.731Z
Status : Analyzed
Published: 2026-04-07T17:16:34.737
Modified: 2026-04-16T18:16:28.757
Link: CVE-2026-35606
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:47:55Z
Github GHSA