CVE-2026-46410
Received
Received - Intake
Information Disclosure in FileBrowser Quantum
Vulnerability report for CVE-2026-46410, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-20
Last updated on: 2026-07-20
Assigner: GitHub, Inc.
Description
Description
FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. Versions 1.3.2-stable and 1.4.1-beta fix the issue. No known workarounds are available.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gtsteffaniak | filebrowser | to 1.3.2-stable (exc) |
| gtsteffaniak | filebrowser | to 1.4.1-beta (exc) |
| gtsteffaniak | filebrowser | 1.4.1 |
| gtsteffaniak | filebrowser | to 1.3.1-stable (inc) |
| gtsteffaniak | filebrowser | to 1.4.0-beta (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |