Skip to content

filebrowser

v2.63.11 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo File Storage & Sync
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

file-browser file-manager file-sharing go material-design self-hosted
+1 more
vue

Affected surfaces

auth breaking_upgrade

Summary

AI summary

Fixes an incomplete security issue that allowed scoped users and share recipients to read/write files outside their permitted scope.

Changes in this release

Bugfix High

Fixes incomplete handling of symlinked directories allowing out-of-scope file access

Fixes incomplete handling of symlinked directories allowing out-of-scope file access

Source: llm_adapter@2026-06-04

Confidence: high

Full changelog

Changelog

  • 1086903c14553545aef0f1a5321011cb139aca3d chore(release): 2.63.11
  • 3471ec2c4b6473831c72ee889cb3c1a6849a1fb1 fix: incomplete fix for symlinked directories let scopes users and public-share recipients read and write files outside of scope

Security Fixes

  • Fixes incomplete fix for symlinked directories that permitted scoped users and public-share recipients to read/write files outside of scope

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track filebrowser

Get notified when new releases ship.

Sign up free

About filebrowser

Web File Browser

All releases →

Related context

Beta — feedback welcome: [email protected]