{"id":"GHSA-5ww9-jg6q-38r7","summary":"File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix","details":"### Summary\nA low-privileged authenticated user of filebrowser (with `create` + `delete` permissions in their own isolated scope) can silently destroy share-link records belonging to any other user — including the administrator — by performing a legitimate DELETE on a file in their own directory whose logical path happens to be a byte-prefix of another user's stored `share.Link.Path`. The file contents of the victim are not exposed, but the victim's share links are irrevocably wiped.\n\n### Details\n`resourceDeleteHandler` in `http/resource.go` cleans up any share records that reference a deleted file by calling:\n\n```go\n// http/resource.go\nerr = d.store.Share.DeleteWithPathPrefix(file.Path)\n```\n\n`file.Path` here is the *logical* path from the URL of the deleting user's request (e.g. `/a`), not the absolute filesystem path. It is passed as-is to the bolt backend:\n\n```go\n// storage/bolt/share.go\nfunc (s shareBackend) DeleteWithPathPrefix(pathPrefix string) error {\n    var links []share.Link\n    if err := s.db.Prefix(\"Path\", pathPrefix, &links); err != nil {\n        return err\n    }\n    for _, link := range links {\n        err = errors.Join(err, s.db.DeleteStruct(&share.Link{Hash: link.Hash}))\n    }\n    return err\n}\n```\n**Why the design contradicts this behavior.** `share.Link` carries a `UserID` field and the application elsewhere treats shares as per-user owned resources. `shareDeleteHandler` explicitly enforces `link.UserID != d.user.ID && !d.user.Perm.Admin → 403`. The file-deletion side-effect path is the only location that bypasses this rule.\n\n\n\n### Impact\n- Integrity: unauthorized deletion of share-link metadata belonging to arbitrary users, including administrators.\n- Availability: effective denial-of-service of the share-link feature — a cooperating (or malicious) low-priv user can wipe the bulk of existing share links by iterating a short set of one- and two-character prefixes.","aliases":["CVE-2026-54097","GO-2026-5159"],"modified":"2026-07-21T15:00:42.291010128Z","published":"2026-06-12T21:00:55Z","database_specific":{"cwe_ids":["CWE-639"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-12T21:00:55Z","nvd_published_at":"2026-06-25T19:16:41Z"},"references":[{"type":"WEB","url":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-5ww9-jg6q-38r7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54097"},{"type":"WEB","url":"https://github.com/filebrowser/filebrowser/commit/0231b7ebdfbe77a6c54027d30c4856c3fd81ee4d"},{"type":"PACKAGE","url":"https://github.com/filebrowser/filebrowser"},{"type":"WEB","url":"https://github.com/filebrowser/filebrowser/releases/tag/v2.63.6"}],"affected":[{"package":{"name":"github.com/filebrowser/filebrowser","ecosystem":"Go","purl":"pkg:golang/github.com/filebrowser/filebrowser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.11.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5ww9-jg6q-38r7/GHSA-5ww9-jg6q-38r7.json"}},{"package":{"name":"github.com/filebrowser/filebrowser/v2","ecosystem":"Go","purl":"pkg:golang/github.com/filebrowser/filebrowser/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.63.6"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.63.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5ww9-jg6q-38r7/GHSA-5ww9-jg6q-38r7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"}]}