—
GO-2026-4474
File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL in github.com/filebrowser/filebrowser
Quick fix
GO-2026-4474 — github.com/filebrowser/filebrowser/v2: upgrade to the fixed version with the command below.
go get github.com/filebrowser/filebrowser/v2@v2.57.1Details
File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL in github.com/filebrowser/filebrowser
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/filebrowser/filebrowser
Introduced in:
0No fixed version published yet for github.com/filebrowser/filebrowser (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/filebrowser/filebrowser/v2
Introduced in:
0Fixed in: 2.57.1Fix
go get github.com/filebrowser/filebrowser/v2@v2.57.1References
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-4mh3-h929-w968[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-25890[ADVISORY]
- https://github.com/filebrowser/filebrowser/commit/489af403a19057f6b6b4b1dc0e48cbb26a202ef9[FIX]
- https://github.com/filebrowser/filebrowser/releases/tag/v2.57.1[WEB]