Skip to content

FileRise

v3.19.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo File Storage & Sync
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

acl docker file-editor file-manager file-upload folder-management
+11 more
javascript multi-file-upload php self-hosted sso twofactor-auth unraid uploader web web-based webdav

Affected surfaces

rce_ssrf

Summary

AI summary

Updates v3.19.0, folder, and https://github.com/error311/FileRise/compare/v3.18.0...v3.19.0 across a mixed release.

Full changelog

Changes 06/26/2026 (v3.19.0)

release(v3.19.0): folder creation hardening

Commit message

release(v3.19.0): folder creation hardening

- security(folder): reject traversal segments before directory creation

Fixed

  • Folder creation hardening
    • Folder creation now rejects . and .. path segments before creating directories.
    • Local folder creation now verifies the parent path stays inside the configured upload root before directory creation.
    • Existing valid child-folder and root-relative nested folder creation behavior is preserved.

v3.19.0

Full Changelog

v3.18.0 → v3.19.0

SHA-256 (zip)

1c53769c1e47eb9591bd7f5fb04ea4fca2e0f1cc3cac5adb2dc4be3ee2c2ce74  FileRise-v3.19.0.zip

Security Fixes

  • Folder creation hardening: rejects `.` and `..` path segments before creating directories and verifies parent paths remain inside the configured upload root.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track FileRise

Get notified when new releases ship.

Sign up free

About FileRise

FileRise – lightweight, self-hosted file manager & storage hub with granular ACLs, resumable uploads, encrypted folders, WebDAV & SSO. Fully Docker / Unraid compatible.

All releases →

Related context

Beta — feedback welcome: [email protected]