HIGHGo

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

CVE-2026-54910Published 5 days agoUpdated 5 days agoSource: OSV

Affected packages

  • github.com/gtsteffaniak/filebrowser/backend

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.31%
EPSS percentile
23.0%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 23%.

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files | HackTribune