The in-memory upload cache deleted expired incomplete uploads with a raw os.Remove on the absolute path it had stored, bypassing ScopedFs entirely. Because the stored path is only lexically cleaned (no symlink evaluation) and os.Remove resolves symlinked parent directories, a Create-only user could register an upload and then, within the 3-minute TTL, swap an in-scope ancestor directory for a symlink so the eviction deleted an arbitrary file outside their scope. Carry a removal callback with each cache entry and invoke it on eviction instead of os.Remove. For TUS uploads the callback deletes via the uploading user's scoped filesystem, whose Remove is guarded by the same within() check that CVE-2026-55667 added, so eviction can no longer follow a symlink out of scope. The redis backend ignores the callback (it never deleted partial files). Refs GHSA-m9f5-2232-frp6 |
||
|---|---|---|
| .github | ||
| auth | ||
| branding | ||
| cmd | ||
| diskcache | ||
| docker | ||
| errors | ||
| files | ||
| fileutils | ||
| frontend | ||
| http | ||
| img | ||
| rules | ||
| runner | ||
| search | ||
| settings | ||
| share | ||
| storage | ||
| users | ||
| version | ||
| www | ||
| .dockerignore | ||
| .gitignore | ||
| .golangci.yml | ||
| .goreleaser.yml | ||
| .versionrc | ||
| CHANGELOG.md | ||
| CODE-OF-CONDUCT.md | ||
| compose.yaml | ||
| CONTRIBUTING.md | ||
| Dockerfile | ||
| Dockerfile.s6 | ||
| go.mod | ||
| go.sum | ||
| LICENSE | ||
| main.go | ||
| README.md | ||
| renovate.json | ||
| SECURITY.md | ||
| Taskfile.yml | ||
| transifex.yml | ||
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview and edit your files. It is a create-your-own-cloud-kind of software where you can just install it on your server, direct it to a path and access your files through a nice web interface.
Documentation
Documentation on how to install, configure, and contribute to this project is hosted at filebrowser.org.
Project Status
This project is a finished product which fulfills its goal: be a single binary web File Browser which can be run by anyone anywhere. That means that File Browser is currently on maintenance-only mode. Therefore, please note the following:
- It can take a while until someone gets back to you. Please be patient.
- Issues are meant to track bugs. Unrelated issues will be converted into discussions.
- The priority is triaging issues, addressing security issues and reviewing pull requests meant to solve bugs.
- No new features are planned. Pull requests for new features will not be reviewed.
Please read @hacdias' personal reflection on the project status.
Contributing
Contributions are always welcome. To start contributing to this project, read our guidelines first.
License
Apache License 2.0 © File Browser Contributors