10 Total advisories
10 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/gtsteffaniak/filebrowser is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.4
GO-2026-5511
FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header)
MEDIUM 6.5
GO-2026-5776
FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks
UNKNOWN
GHSA-r4v7-6wcg-ghj5
FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks in github.com/gtsteffaniak/filebrowser
UNKNOWN
GHSA-mmpx-jh39-wrv6
FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header) in github.com/gtsteffaniak/filebrowser
CRITICAL 9.1
CVE-2026-44542
FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion
UNKNOWN
CVE-2026-44542
FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion in github.com/gtsteffaniak/filebrowser
UNKNOWN
CVE-2026-46410
FileBrowser Quantum: unauthenticated user share share info
UNKNOWN
CVE-2026-46410
FileBrowser Quantum: unauthenticated user share share info in github.com/gtsteffaniak/filebrowser
HIGH 8.9
CVE-2026-30934
FileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse)
UNKNOWN
CVE-2026-30934
FileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse) in github.com/gtsteffaniak/filebrowser
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes