{"uid":"cap_BIq4moU1iNX7hQ54nN-9e","slug":"tenjin-security-briefs-filebrowser-subtitle-endpoint-path-traversal-f76a17e4","name":"Tenjin Security Briefs – FileBrowser Subtitle Endpoint Path Traversal Advisory","description":"FileBrowser Quantum's July 31 reviewed advisory says any authenticated user could use the subtitle handler to read host text files outside their storage scope; affected versions include 1.3.3-stable and 1.4.2-beta, with the beta fix in v1.4.3-beta.","url":"https://tenjin.blog/api/read/security-briefs/security-briefs-daily-filebrowser-s-subtitle-endpoint-crossed-the-storage-root","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"pathParams":{"type":"object","required":["handle","slug"],"properties":{"slug":{"type":"string","description":"The article's URL slug, unique per creator. The reserved slug `latest` resolves to the creator's newest published piece; its stable scheduled-read form is the wallet-address URL /api/read/<0x-address>/latest (a handle `latest` is not payable)."},"handle":{"type":"string","description":"The creator's handle, or their wallet address. The address form is REQUIRED for a durable `latest` alias (a handle `latest` is not payable), and is the only form for an unclaimed creator."}}},"queryParams":{"type":"object","required":[],"properties":{},"additionalProperties":false}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_uxTmrbuzIOCeGtfk7Z6CK","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns the full text of a paid security brief article about FileBrowser Quantum's subtitle handler path-traversal vulnerability (CVE advisory dated July 31)","exampleAgentPrompt":"Pull the Tenjin security brief on FileBrowser Quantum's subtitle endpoint path traversal vulnerability — the one from July 31 that covers affected versions 1.3.3-stable and 1.4.2-beta and the fix in v1.4.3-beta.","exampleUseCases":[{"title":"Patch assessment for FileBrowser deployments","prompt":"I'm running FileBrowser Quantum 1.3.3-stable in production — can you fetch the Tenjin security brief about that subtitle handler vulnerability so I can assess whether I need to patch urgently?"},{"title":"Security briefing for dev team on file manager CVE","prompt":"Get me the full Tenjin advisory on the FileBrowser subtitle endpoint bug where authenticated users could read host files outside their storage scope — I need to share it with the team."},{"title":"Tracking fix version for FileBrowser beta branch","prompt":"What version of FileBrowser Quantum fixed the subtitle handler path traversal issue? Fetch the Tenjin brief on it — specifically the one covering the beta fix in v1.4.3-beta."}],"resultDescription":"The full article text of the Tenjin security brief, describing the FileBrowser Quantum subtitle handler vulnerability, the mechanism by which authenticated users could read host text files outside their storage scope, the affected versions (1.3.3-stable and 1.4.2-beta), and the fix introduced in v1.4.3-beta, as published in the July 31 daily advisory.","failureModes":["Incorrect or missing handle/slug path params returns 404 article not found","Payment failure via x402 protocol prevents content delivery","Slug 'latest' used with handle 'latest' is not payable and will fail","Article may have been updated or replaced since crawl; content could differ","Network timeout or upstream blog unavailability returns 5xx error"],"whenToPreferThis":"Use this endpoint when you specifically need the full text of the FileBrowser Quantum subtitle handler path traversal advisory from Tenjin's security briefs feed. Prefer this over generic web search when you need the structured, paid-access article with complete vulnerability details, affected versions, and fix guidance in a single deterministic fetch.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:58:58.072Z","isFirstParty":false}