<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 12:37:49 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275261</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275261</link>
      <description>EUVD-2026-275261</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275261</guid>
    </item>
    <item>
      <title>fkie_cve-2026-30933</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-30933</link>
      <description>&lt;p&gt;FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-30933</guid>
    </item>
    <item>
      <title>GHSA-525j-95gf-766f — FileBrowser Quantum: Password-Protected Share Bypass via /public/api/share/info</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-525j-95gf-766f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gtsteffaniak/filebrowser/backend&lt;/p&gt;
&lt;p&gt;### Summary
The remediation for CVE-2026-27611 appears incomplete.  Password protected shares still disclose tokenized downloadURL via /public/api/share/info in docker image gtstef/filebrowser:1.3.1-webdav-2.&lt;/p&gt;
&lt;p&gt;### Details
The issue stems from two flaws:
1. Tokenized download URLs are written into the persistent share model
```
backend/http/share.go
convertToFrontendShareResponse(line 63)
s.DownloadURL = getShareURL(r, s.Hash, true, s.Token)
```
2. The public endpoint:
```
GET /public/api/share/info
returns shareLink.CommonShare without clearing DownloadURL.
```&lt;/p&gt;
&lt;p&gt;Since Token is set for password-protected shares, and getShareURL(..., true, token) embeds it as a query parameter, the public API discloses a valid bearer download capability.&lt;/p&gt;
&lt;p&gt;The previous patch removed token generation in one handler but did not address the persisted DownloadURL values/Public reflection of existing DownloadURL&lt;/p&gt;
&lt;p&gt;### PoC
1. Create a password protected share as an authenticated user&lt;/p&gt;
&lt;p&gt;2. Copy the public share URL (the clipboard WITHOUT an arrow)  
    `http://yourdomain/public/share/yoursharedhash`  
    Example:   
    `http://yourdomain/public/share/2EBGbXgXg5dpw-nK0RG6vw`&lt;/p&gt;
&lt;p&gt;3. Query the public share endpoint via curl request:  
`curl &amp;#39;http://yourdomain/public/api/share/info?hash=(your-share-hash)&amp;#39; -H &amp;#39;Accept: */*&amp;#39;  `  
Example:  
`curl &amp;#39;http://yourdomain/public/api/share/info?hash=2EBGbXgXg5dpw-nK0RG6vw&amp;#39; -H &amp;#39;Accept: */*&amp;#39;  `  
  
    Response includes:
    ```
    {
        &amp;#34;shareTheme&amp;#34;: &amp;#34;defa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gtsteffaniak/filebrowser/backend&lt;/p&gt;
&lt;p&gt;### Summary
The remediation for CVE-2026-27611 appears incomplete.  Password protected shares still disclose tokenized downloadURL via /public/api/share/info in docker image gtstef/filebrowser:1.3.1-webdav-2.&lt;/p&gt;
&lt;p&gt;### Details
The issue stems from two flaws:
1. Tokenized download URLs are written into the persistent share model
```
backend/http/share.go
convertToFrontendShareResponse(line 63)
s.DownloadURL = getShareURL(r, s.Hash, true, s.Token)
```
2. The public endpoint:
```
GET /public/api/share/info
returns shareLink.CommonShare without clearing DownloadURL.
```&lt;/p&gt;
&lt;p&gt;Since Token is set for password-protected shares, and getShareURL(..., true, token) embeds it as a query parameter, the public API discloses a valid bearer download capability.&lt;/p&gt;
&lt;p&gt;The previous patch removed token generation in one handler but did not address the persisted DownloadURL values/Public reflection of existing DownloadURL&lt;/p&gt;
&lt;p&gt;### PoC
1. Create a password protected share as an authenticated user&lt;/p&gt;
&lt;p&gt;2. Copy the public share URL (the clipboard WITHOUT an arrow)  
    `http://yourdomain/public/share/yoursharedhash`  
    Example:   
    `http://yourdomain/public/share/2EBGbXgXg5dpw-nK0RG6vw`&lt;/p&gt;
&lt;p&gt;3. Query the public share endpoint via curl request:  
`curl &amp;#39;http://yourdomain/public/api/share/info?hash=(your-share-hash)&amp;#39; -H &amp;#39;Accept: */*&amp;#39;  `  
Example:  
`curl &amp;#39;http://yourdomain/public/api/share/info?hash=2EBGbXgXg5dpw-nK0RG6vw&amp;#39; -H &amp;#39;Accept: */*&amp;#39;  `  
  
    Response includes:
    ```
    {
        &amp;#34;shareTheme&amp;#34;: &amp;#34;defa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-525j-95gf-766f</guid>
    </item>
  </channel>
</rss>
