VDB
Sign up
—

GO-2026-5511

FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header) in github.com/gtsteffaniak/filebrowser

Quick fix

GO-2026-5511 — github.com/gtsteffaniak/filebrowser: upgrade to the fixed version with the command below.

go get github.com/gtsteffaniak/filebrowser@v0.0.0-20260501184955-6bfc3974192e

Details

FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header) in github.com/gtsteffaniak/filebrowser

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/gtsteffaniak/filebrowser
Introduced in: 0Fixed in: 0.0.0-20260501184955-6bfc3974192e
Fixgo get github.com/gtsteffaniak/filebrowser@v0.0.0-20260501184955-6bfc3974192e

References