<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T11:17:52.138918+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275261</id>
    <title>EUVD-2026-275261</title>
    <updated>2026-10-06T11:17:52.191229+00:00</updated>
    <content>EUVD-2026-275261</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275261"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30933</id>
    <title>fkie_cve-2026-30933</title>
    <updated>2026-10-06T11:17:52.191283+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-30933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-525j-95gf-766f</id>
    <title>GHSA-525j-95gf-766f — FileBrowser Quantum: Password-Protected Share Bypass via /public/api/share/info</title>
    <updated>2026-10-06T11:17:52.191321+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gtsteffaniak/filebrowser/backend</p>
<p>### Summary
The remediation for CVE-2026-27611 appears incomplete.  Password protected shares still disclose tokenized downloadURL via /public/api/share/info in docker image gtstef/filebrowser:1.3.1-webdav-2.</p>
<p>### Details
The issue stems from two flaws:
1. Tokenized download URLs are written into the persistent share model
```
backend/http/share.go
convertToFrontendShareResponse(line 63)
s.DownloadURL = getShareURL(r, s.Hash, true, s.Token)
```
2. The public endpoint:
```
GET /public/api/share/info
returns shareLink.CommonShare without clearing DownloadURL.
```</p>
<p>Since Token is set for password-protected shares, and getShareURL(..., true, token) embeds it as a query parameter, the public API discloses a valid bearer download capability.</p>
<p>The previous patch removed token generation in one handler but did not address the persisted DownloadURL values/Public reflection of existing DownloadURL</p>
<p>### PoC
1. Create a password protected share as an authenticated user</p>
<p>2. Copy the public share URL (the clipboard WITHOUT an arrow)  
    `http://yourdomain/public/share/yoursharedhash`  
    Example:   
    `http://yourdomain/public/share/2EBGbXgXg5dpw-nK0RG6vw`</p>
<p>3. Query the public share endpoint via curl request:  
`curl 'http://yourdomain/public/api/share/info?hash=(your-share-hash)' -H 'Accept: */*'  `  
Example:  
`curl 'http://yourdomain/public/api/share/info?hash=2EBGbXgXg5dpw-nK0RG6vw' -H 'Accept: */*'  `  
  
    Response includes:
    ```
    {
        "shareTheme": "defa…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-525j-95gf-766f"/>
  </entry>
</feed>
