These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-54910 is a high-severity path traversal vulnerability in FileBrowser Quantum, a free, self-hosted, web-based file manager. An attacker can exploit this vulnerability to read any text file readable by the server process, potentially leading to unauthorized access to sensitive data. The vulnerability is caused by the `subtitlesHandler` endpoint accepting two user-controlled query parameters, `path` [truncated]
CVE-2026-54685 is a MEDIUM severity vulnerability in FileBrowser Quantum, a free, self-hosted, web-based file manager. The `/api/auth/login` authentication endpoint is vulnerable to a timing attack. When a non-existent username is supplied, the server returns a response quickly. However, when a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the [truncated]
CVE-2026-46410 is a high-severity vulnerability in FileBrowser Quantum, a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. The CVSS score is 8.7, indicating a high severity level. The vulnerability class is related to sensitive information leaks. The affected product is FileBrowser Quantum. The likely operationa [truncated]
CVE-2026-48777 is a critical vulnerability in FileBrowser Quantum, a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta, and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go. This vulnerability allows an attacker to move, copy, or rename arbitrary files within the share owner's source root by exploiting a public share l [truncated]