blob: cb350711c749dec73b608515db8597d70df04b44 [file] [edit]
id: GO-2026-4660
modules:
- module: github.com/gtsteffaniak/filebrowser
versions:
- fixed: 0.0.0-20260307130210-09713b32a5f6
summary: |-
FileBrowser Quantum: Stored XSS in public share page via unsanitized share
metadata (text/template misuse) in github.com/gtsteffaniak/filebrowser
cves:
- CVE-2026-30934
ghsas:
- GHSA-r633-fcgp-m532
references:
- advisory: https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-r633-fcgp-m532
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-30934
- web: https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.2.2-stable
- web: https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.1-beta
notes:
- fix: 'github.com/gtsteffaniak/filebrowser: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
source:
id: GHSA-r633-fcgp-m532
created: 2026-03-10T16:28:33.503955-04:00
review_status: UNREVIEWED