This release includes 1 security fix for security teams reviewing exposed deployments.
Affected surfaces
Summary
AI summaryCritical path traversal vulnerability in public share PATCH fixed (GHSA-qqqm-5547-774).
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Path traversal in public share PATCH allows file ops outside shared directory Path traversal in public share PATCH allows file ops outside shared directory Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
| Bugfix | Medium |
Fixed path slash issue on Windows Fixed path slash issue on Windows Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
— |
Full changelog
What's Changed
Security:
- [Critical] Path traversal in public share PATCH allows file ops outside shared directory -- thanks @fg0x0 and @Revanth011 for reporting GHSA-qqqm-5547-774
Notes:
- updated share hash middleware (#2443)
- fix path slash issue on windows (#2451) (#2433) (#2419)
Full Changelog: https://github.com/gtsteffaniak/filebrowser/compare/v1.3.2-stable...v1.3.3-stable
Security Fixes
- GHSA-qqqm-5547-774 — Critical path traversal in public share PATCH allowing file operations outside the shared directory
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]