THREAT OPS › Threat News › [GHSA] GHSA-vvp7-h4fj-m28w (high) — FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
[GHSA] GHSA-vvp7-h4fj-m28w (high) — FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
GHSA-vvp7-h4fj-m28w Severity: high CVE: CVE-2026-54910
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
### Summary
The `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two inde
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-54910cve
Original source: https://github.com/advisories/GHSA-vvp7-h4fj-m28w