PT-2026-72007 · Unknown · Filebrowser
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FileBrowser versions prior to 2.63.19
Description
Authenticated users can write arbitrary data to disk because the software fails to enforce the declared
Upload-Length in the TUS resumable-upload PATCH endpoint. This allows attackers to send oversized request bodies that exceed the declared upload length, potentially exhausting available disk space and causing service unavailability.Recommendations
Update to version 2.63.19 or later.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filebrowser