CVE-2026-30934: FileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse)

Published Mar 9, 2026
·
Updated

Summary Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/<hash> without context-aware escaping. The server uses text/template instead of html/template, allowing injected scripts to execute when victims visit the share URL.

Details The server renders public/index.html using text/template and injects user-controlled share fields (title/description/etc.) into HTML contexts. text/template does not perform HTML contextual escaping like html/template. Because share metadata is persistent, the payload becomes stored and executes whenever a victim opens the affected share page.

Relevant code paths: - backend/http/static.go (template rendering and share metadata assignment) - backend/http/httpRouter.go (template initialization) - frontend/public/index.html (insertion points for title/description and related fields)

PoC 1. Login as a user with share creation permission. 2. Create a share (POST /api/share) with malicious metadata: - title = </title><script>alert("xss")</script><title> 3. Open the resulting /public/share/<hash> URL in a browser. 4. Expected: Payload is safely escaped and displayed as text. 5. Actual: JavaScript executes in victim's browser (stored XSS).

Tested on Docker image: gtstef/filebrowser:stable (version v1.2.1-stable).

Impact - Arbitrary script execution in application origin. - Potential account/session compromise, CSRF-like action execution, data exfiltration from authenticated contexts. - Affects anyone (including unauthenticated visitors) opening the malicious share URL. - The XSS is stored and persistent — no social engineering beyond sharing the link is required.

Other sources

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/<hash> without context-aware escaping. The server uses text/template instead of html/template, allowing injected scripts to execute when victims visit the share URL. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable.

MITRE

Affected Software

4 affected componentsFixes available
go/github.com/gtsteffaniak/filebrowser<0.0.0-20260307130210-09713b32a5f6
0.0.0-20260307130210-09713b32a5f6
Filebrowser Filebrowser<=1.2.9
Filebrowser Filebrowser=1.2.1-stable
Filebrowser Filebrowser=1.3.0-beta

Event History

Mar 9, 2026
Advisory Published
via GitHub·07:48 PM
Data Sourced
via GitHub·07:48 PM
DescriptionSeverityWeaknessAffected Software
Mar 10, 2026
CVE Published
via MITRE·04:12 PM
Data Sourced
via MITRE·04:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
Affected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-30934?

CVE-2026-30934 has a moderate severity due to the potential for stored XSS attacks.

2

How do I fix CVE-2026-30934?

To fix CVE-2026-30934, upgrade to version 0.0.0-20260307130210-09713b32a5f6 or later of the FileBrowser software.

3

What type of vulnerability is CVE-2026-30934?

CVE-2026-30934 is a stored cross-site scripting (XSS) vulnerability.

4

Which software versions are affected by CVE-2026-30934?

CVE-2026-30934 affects versions of FileBrowser prior to 0.0.0-20260307130210-09713b32a5f6.

5

How does CVE-2026-30934 exploit its vulnerability?

CVE-2026-30934 exploits the vulnerability through unsanitized share metadata fields rendered into HTML.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203