CVE-2026-62843: Filebrowser
Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as ..\..\evil.sh into the archive entry ../../evil.sh, allowing a user with upload permission to plant a backslash-named file that escapes the extraction directory when another user downloads and extracts the generated zip or tar archive. This issue is fixed in version 2.63.17.
Affected products
- Filebrowser Filebrowser: from 2.63.6, before 2.63.17 (fixed in 2.63.17)
Published 2026-07-15. Last modified 2026-07-15.