Impact
File Browser is a web‑based file management, which incorrectly validates a dangling symlink’s nearest existing ancestor as in scope and then follows the symlink during file creation. An authenticated user with Create and Modify permissions can create files at arbitrary locations outside the user of files that the user should not be able to access.
Affected Systems
The flaw affects all File Browser installations of the filebrowser:filebrowser product running versions earlier than 2.63.16. Version 2.63. users should ensure they are running 2.63.16 or newer.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. EPSS score of < 1%, and the vulnerability is not listed in the CISA KEV catalog, implying a lower current significance an authenticated session with Create/Modify rights—any legitimate user with those privileges can exploit the flaw. As File Browser operates through a web interface, a remote attacker who can obtain valid credentials or bypass authentication controls could also trigger this issue.
OpenCVE Enrichment
Github GHSA