CVE-2026-54097: File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
A low-privileged authenticated user of filebrowser (with create + delete permissions in their own isolated scope) can silently destroy share-link records belonging to any other user — including the administrator — by performing a legitimate DELETE on a file in their own directory whose logical path happens to be a byte-prefix of another user’s stored share.Link.Path. The file contents of the victim are not exposed, but the victim’s share links are irrevocably wiped.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-54097 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →