Sitelet https://github.com/filebrowser/filebrowser/pull/5889
Skip to content
This repository was archived by the owner on Aug 31, 2026. It is now read-only.

fix: enforce directory boundary in rule path matching - #5889

Merged
hacdias merged 1 commit into
filebrowser:masterfrom
kodareef5:fix/rule-prefix-boundary-check
Apr 4, 2026
Merged

hacdias merged 1 commit into
filebrowser:masterfrom
kodareef5:fix/rule-prefix-boundary-check

Conversation

@kodareef5

Copy link
Copy Markdown
Contributor

Summary

  • Rule.Matches() used strings.HasPrefix() without ensuring the match ends at a directory boundary
  • A rule for /uploads would also match /uploads_backup/, granting or denying access to unintended directories
  • Appends a trailing / to the prefix before comparison, and adds an exact-match check
  • Adds 8 test cases covering exact match, child paths, sibling prefixes, root rules, and nested paths

Ref: GHSA-5q48-q4fm-g3m6

The Matches() function used strings.HasPrefix() without ensuring the
match ends at a directory boundary. A rule for "/uploads" would also
match "/uploads_backup/", granting or denying access to unintended
directories. Ensure the prefix ends with a separator before comparing.

Ref: GHSA-5q48-q4fm-g3m6
@kodareef5
kodareef5 requested a review from a team as a code owner April 4, 2026 15:11
@hacdias
hacdias merged commit 8adf127 into filebrowser:master Apr 4, 2026
7 checks passed
kumaraguru1735 pushed a commit to kumaraguru1735/filebrowser-laravel that referenced this pull request Apr 8, 2026
- filebrowser#5891: Check download perm for binary files in resourceGet
- filebrowser#5889: Reject .. paths before realpath (defense in depth)
- filebrowser#5888: Verify share owner download perm on public access
- filebrowser#5848: Normalize double slashes in TUS upload paths
- Add X-Content-Type-Options for epub/svg/html inline previews

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants