Impact
FileBrowser Quantum is a free, self-hosted, web‑based file manager. In versions before 1.3.2‑stable and 1.4.1‑beta, an unauthenticated user can query the share endpoint and obtain detailed share metadata, including the source and path of files. This allows an attacker to discover sensitive internal directory structure and other file information that could be leveraged for further attacks.
Affected Systems
The affected product is FileBrowser Quantum developed by the github user gtsteffaniak. Versions prior to 1.3.2-stable and 1.4.1-beta are vulnerable. Users running these releases need to assess the environment to determine whether share information is exposed to the internet.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity and a high likelihood of exploitation if the web service is exposed. The EPSS score is less than 1%, indicating a low probability of exploitation in the general population, but the vulnerability remains a concern for exposed instances. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote unauthenticated access via the web interface; an attacker only needs to know the URL of the file share endpoint, which is typically publicly reachable if the instance is not behind authentication or a firewall. Once accessed, the attacker can enumerate files and directories, increasing the risk of further compromise.
OpenCVE Enrichment
Github GHSA