SB20260408134 - Path traversal in FileBrowser



SB20260408134 - Path traversal in FileBrowser

Published: April 8, 2026

Security Bulletin ID SB20260408134
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Path traversal (CVE-ID: CVE-2026-28492)

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in the withHashFile middleware in http/public.go when handling public share link requests for a shared directory. A remote attacker can use a public share link to browse sibling directories and download files outside the shared directory to disclose sensitive information.

This affects directory listing via /api/public/share/{hash} and file download via /api/public/dl/{hash}/path. Password-protected shares are affected after the share password is provided.


Remediation

Install update from vendor's website.