—
GO-2026-5511
FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header) in github.com/gtsteffaniak/filebrowser
Quick fix
GO-2026-5511 — github.com/gtsteffaniak/filebrowser: upgrade to the fixed version with the command below.
go get github.com/gtsteffaniak/filebrowser@v0.0.0-20260501184955-6bfc3974192eDetails
FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header) in github.com/gtsteffaniak/filebrowser
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/gtsteffaniak/filebrowser
Introduced in:
0Fixed in: 0.0.0-20260501184955-6bfc3974192eFix
go get github.com/gtsteffaniak/filebrowser@v0.0.0-20260501184955-6bfc3974192e