Impact
The vulnerability allows an authenticated user with Create permission to delete arbitrary files outside the intended scope by manipulating the TUS upload cache eviction mechanism. During the cache time‑to‑live window, an attacker can replace an ancestor directory with a symlink so that the underlying os.Remove call targets an out-of-scope file. This leads to unintended data loss or modification, impacting the confidentiality, integrity, and availability of the affected system.
Affected Systems
filebrowser filebrowser users running any version before 2.63.19 are affected. The issue is present in all installations of the TUS upload feature in such versions.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity. The exploit requires authenticated access with Create rights and knowledge of cache eviction timing, which makes the attack vector a remote, authenticated attack. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, but the potential for arbitrary deletion gives it a high risk for systems that lack strict permission controls or monitoring.
OpenCVE Enrichment