—
GO-2026-4660
FileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse) in github.com/gtsteffaniak/filebrowser
Quick fix
GO-2026-4660 — github.com/gtsteffaniak/filebrowser: upgrade to the fixed version with the command below.
go get github.com/gtsteffaniak/filebrowser@v0.0.0-20260307130210-09713b32a5f6Details
FileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse) in github.com/gtsteffaniak/filebrowser
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/gtsteffaniak/filebrowser
Introduced in:
0Fixed in: 0.0.0-20260307130210-09713b32a5f6Fix
go get github.com/gtsteffaniak/filebrowser@v0.0.0-20260307130210-09713b32a5f6