Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-68j5-4m99-w9w9
No affected components available
Summary
A permission enforcement flaw allows users without download privileges (download=false) to still expose and retrieve file content via public share links when they retain share privileges (share=true). This bypasses intended access control policy and enables unauthorized data exfiltration to unauthenticated users. Where download restrictions are used for data-loss prevention or role separation.
Details
The backend applies inconsistent authorization checks across download paths:
- Direct raw download correctly enforces
Perm.Download:- [raw.go](filebrowser/http/raw.go:82)
- Share creation only enforces
Perm.Share:- [share.go](filebrowser/http/share.go:21)
- Public share/download handlers serve shared content without verifying owner
Perm.Download:
As a result, a user who is blocked from direct downloads can create a share and obtain the same file via /api/public/dl/<hash>.
PoC
- Create a non-admin user with:
perm.share = trueperm.download = false
- Login as that user and upload a PDF file:
POST /api/resources/nodl_secret_<rand>.pdfwithContent-Type: application/pdf
- Verify direct raw download is denied:
GET /api/raw/nodl_secret_<rand>.pdf- Expected and observed:
202 Accepted(blocked)
- Create share for same file:
POST /api/share/nodl_secret_<rand>.pdf- Observed:
200, response includeshash(example:qxfK3JMG)
- Download publicly without authentication:
GET /api/public/dl/<hash>- Observed (vulnerable):
200,Content-Type: application/pdf, and PDF bytes are returned
Live evidence captured (March 1, 2026):
create user:201create file:200direct /api/raw:202 Acceptedcreate share:200public download /api/public/dl/mxK-ppZb:200public download content-type:application/pdfpublic download body length:327bytes
Impact
This is an access control / authorization policy bypass vulnerability.
- Who can exploit: Any authenticated user granted
share=truebut denieddownload. - Who is impacted: Operators and organizations relying on download restrictions to prevent data export.
- What can happen: Restricted users can still distribute and retrieve files publicly, including unauthenticated access through share URLs.
The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker needs basic access or low-level privileges. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a high impact on the confidentiality of the information.
Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard