THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vvp7-h4fj-m28w (high) — FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

[GHSA] GHSA-vvp7-h4fj-m28w (high) — FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

medgithub_advisoriesPublished 2026-07-31

GHSA-vvp7-h4fj-m28w Severity: high CVE: CVE-2026-54910

FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files

### Summary

The `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two inde

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vvp7-h4fj-m28w