VDB
GO-2026-4606
GO-2026-4606
PUBLISHED
File Browser's TUS Delete Endpoint Bypasses Delete Permission Check in github.com/filebrowser/filebrowser
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | filebrowser/filebrowser/v2 | 0, 0 |
| github.com | filebrowser/filebrowser | 0, 0 |
Timeline
- Mar 10, 2026 CVE Published
- Mar 23, 2026 CVE Updated
- May 1, 2026 Security Advisory
References
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-79pf-vx4x-7jmm advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-29188 advisory
- https://github.com/filebrowser/filebrowser/commit/7ed1425115be602c2b23236c410098ea2d74b42f patch
- https://github.com/filebrowser/filebrowser/releases/tag/v2.61.1 url