CVE-2026-35605 | filebrowser File Browser up to 2.63.0 rules/rules.go Matches path traversal (GHSA-5q48-q4fm-g3m6)
A vulnerability marked as critical has been reported in filebrowser File Browser up to 2.63.0. Impacted is the function Matches of the file rules/rules.go. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-35605. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.