Skip to content

filebrowser

v2.63.19 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 2d File Storage & Sync
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

file-browser file-manager file-sharing go material-design self-hosted
+1 more
vue

Affected surfaces

auth rce_ssrf

Summary

AI summary

Updates http, storage, and auth across a mixed release.

Full changelog

Changelog

  • 328f629181888760f3c8b3ff9f3b5bec50f4e54f chore(release): 2.63.19
  • 4c3cb4bc9b7a165ef42cf79f0e0842bbc42e26fd test(http): cover TUS Upload-Length enforcement
  • 3213b605be4f8f9938b093a3384d404d66e7a28b test(http): cover scope-safe removal on TUS upload eviction
  • 610e0b09e93e4b1940b9d50c9b0374ccab02a0d5 test(http): cover download-permission gate on the checksum branch
  • 7453c78c9877cbee71dfbad06326d450102e59de test(storage): cover case-insensitive GetByScope matching
  • cd5749dff8bbc2c16f99b7a127651a9d8e0da694 test(auth): cover per-user scope isolation for proxy and hook provisioning
  • 4daddec6f200b03a721197d8c0b4b652c994894e fix(http): enforce declared Upload-Length on TUS uploads
  • 9bd79c3aaeb4a55b0e69cf8976c4a258db2f5e06 fix(http): delete abandoned TUS uploads through the scoped filesystem
  • 6c69b5cd895e15b29e563200a9a6dfc27b06525e fix(http): enforce download permission on the checksum branch
  • 4b8a8d72ce554dde378b5091da74aa930ea18327 fix(storage): reject case-folded home directory collisions
  • 8ddd3d1db9b9f5727d0bf96ea0e7d9a25a8692b4 fix(auth): isolate auto-provisioned proxy and hook users to their own home
  • 9fffee387ff102728e47531ebc6cf5d1dd39bbf1 docs: remove go report
  • 5a12cad54855b6bb3189f0d5ea93942647989ba5 docs: update readme
  • 6232686e222eae9e627c8c432e3e1d6796782971 chore: update translations
  • b21b1245ae1b57f031b2f5d787f32a17532402c0 fix: accessibility and security improvements (#6033)
  • 7361d91ea2e8cc200a0f40ac84adcd02aedc9ed2 fix(upload): handle encoded path conflicts safely (#6040)
  • c05c66814891c3cccef394162e428444b53394e4 fix: process --FollowExternalSymlinks
  • b7dc392838f11d188f0bc0f2a1a99fad3f7dca03 docs: fix typo
  • ac46cf06719575477d5125e7472037c204b3702d fix: return error instead of panicking on an unreadable directory during copy (#6020)
  • f0785391bf11cc8ec53bff7b2f36a29a02f536dc chore: update translations (#6019)
  • 9b78324d773c790951cc6a97840c4b55f66b5f3d fix(http): run upload hooks for directories (#6034)

Security Fixes

  • Fix: accessibility and security improvements (#6033)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track filebrowser

Get notified when new releases ship.

Sign up free

About filebrowser

Web File Browser

All releases →

Related context

Beta — feedback welcome: [email protected]