github.com/gtsteffaniak/filebrowser
v0.3.4
#513 most downloaded on Go modules
gtsteffaniak/filebrowser
What this package is like to depend on
Last release 2 days ago
22 Aug 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 15 of 15 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
345 releases · first in 2023
244 releases in the last 12 months
see the full history below
Release timeline
345 releases · Jun 2023 to Aug 2026Releases
latest 60 of 345-
v2.0.1-beta+incompatible15 Aug 2026 pre-releaseNothing published for this version
-
v2.0.0-preview-5+incompatible05 Aug 2026 pre-releaseNothing published for this version
-
v2.0.0-preview-4+incompatible02 Aug 2026 pre-releaseNothing published for this version
-
v2.0.0-preview-3+incompatible24 Jul 2026 pre-releaseNothing published for this version
-
v2.0.0-preview-2+incompatible24 Jul 2026 pre-releaseNothing published for this version
-
v2.0.0-preview-1+incompatible23 Jul 2026 pre-releaseNothing published for this version
-
v2.0.0-beta+incompatible07 Aug 2026 pre-releaseNothing published for this version
-
v1.5.5-beta07 Aug 2026 pre-releaseRelease notes
Open source →What's Changed
BugFixes:
- fix uncustomized (minimal) API tokens creation needed by webdav clients (#2503)
Full Changelog: v1.5.4-beta...v1.5.5-beta
-
v1.5.4-beta02 Aug 2026 pre-releaseRelease notes
Open source →What's Changed
- remove pwa short name and use 30 char name cap by @gtsteffaniak in #2701
- fix search key bug by @gtsteffaniak in #2702
Full Changelog: v1.5.3-beta...v1.5.4-beta
-
v1.5.3-stable22 Aug 2026 pre-releaseRelease notes
Open source →What's Changed
BugFixes:
- windows backslash inserted into directory URLs causing malformed paths and path escapes from parent (#2815) (#2816)
- root download of a shared file/folder returns HTTP 500 (#2807) (#2810) (#2821) (#2818)
- OnlyOffice is inaccessible if share has optional password (#2811)
Full Changelog: v1.5.2-stable...v1.5.3-stable
-
v1.5.3-beta31 Jul 2026 pre-releaseRelease notes
Open source →What's Changed
BugFixes:
- fix probe canShare with the real file, not a fixed text/plain stand-in (#2664)
- When the logout button is pressed, the user is redirected to an invalid URL that does not honor baseURL / externalUrl (#2657)
- fix redirect to login when an authenticated request returns 401 (expired session) (#2679)
New Contributors
- @myUdav4iik made their first contribution in #2664
- @e-tang made their first contribution in #2679
Full Changelog: v1.5.2-beta...v1.5.3-beta
-
v1.5.2-stable15 Aug 2026 pre-releaseRelease notes
Open source →What's Changed
Security:
- [High] Symlink following on read paths no longer escapes source or user/share scope (GHSA-mgqf-5mf5-prfj) -- thanks @je-lv @KasperBuilds
- [High] Share create/update could set delete/modify/create flags beyond the owner's permissions; POST /api/share with hash could update another user's share (GHSA-x79q-5hqm-x839) -- thanks @pant0m
- [High] PATCH /api/share could re-point a share outside the owner's scope (GHSA-wfjp-qhvc-69wp) -- thanks @maximeborges
- [High] Public upload ACL check used scope-stripped path, bypassing per-folder DENY rules (GHSA-qv53-4557-m65h) -- thanks @hypnguyen1209
- [Moderate] Absolute paths in API path/file parameters could bypass user scope and read files outside the source mount (GHSA-rqqq-wv83-rp74) -- thanks @Wei-Leo
- [Moderate] Authenticated upload and pause endpoints checked access rules on scope-relative paths, bypassing per-folder DENY rules (GHSA-cw65-p35p-633w) -- thanks @5ud0er
- [Moderate] Logout did not invalidate session JWTs with equivalent Base64URL spellings (GHSA-8m35-wcjh-95q7) -- thanks @corbanvilla @soh3e @dderpym (This vulnerability was discovered as part of a U.C. Berkeley security research project by: Corban Villa, Sohee Kim, and Austin Chu)
- [Moderate] Stored XSS via unsanitized DOCX hyperlink in DocViewer (GHSA-9wm6-jcjh-3m8c) -- thanks @karen93shieh @je-lv @EclipsSec
- [Moderate] Revoked JWTs could still authenticate on public-share and withOrWithoutUser routes until natural expiry, bypassing logout and Api-permission revocation on that surface (GHSA-4wmj-rq3c-m65v) -- thanks @hypnguyen1209
Full Changelog: v1.5.1-stable...v1.5.2-stable
-
v1.5.2-beta17 Jul 2026 pre-releaseNothing published for this version
-
v1.5.1-stable07 Aug 2026 pre-releaseRelease notes
Open source →What's Changed (since the last stable v1.5.0)
Notes:
- PWA installation name now capped at 30 characters instead of 12 (#2699)
BugFixes:
- fix forward slash blocked in text fields when the search shortcut listener intercepts
/(#2696) - fix probe canShare with the real file, not a fixed text/plain stand-in (#2664)
- When the logout button is pressed, the user is redirected to an invalid URL that does not honor baseURL / externalUrl (#2657)
- fix redirect to login when an authenticated request returns 401 (expired session)
- fix uncustomized (minimal) API tokens creation needed by webdav clients (#2503)
Full Changelog: v1.5.0-stable...v1.5.1-stable
-
v1.5.1-beta11 Jul 2026 pre-releaseNothing published for this version
-
v1.5.0-stable17 Jul 2026 pre-releaseNothing published for this version
-
v1.5.0-beta13 Jun 2026 pre-releaseNothing published for this version
-
v1.4.4-beta10 Jun 2026 pre-releaseNothing published for this version
-
v1.4.3-beta10 Jun 2026 pre-releaseNothing published for this version
-
v1.4.2-beta22 May 2026 pre-releaseNothing published for this version
-
v1.4.1-beta14 May 2026 pre-releaseNothing published for this version
-
v1.4.0-stable10 Jun 2026 pre-releaseNothing published for this version
-
v1.4.0-beta13 May 2026 pre-releaseNothing published for this version
-
v1.3.10-beta05 May 2026 pre-releaseNothing published for this version
-
v1.3.9-beta01 May 2026 pre-releaseNothing published for this version
-
v1.3.8-beta29 Apr 2026 pre-releaseNothing published for this version
-
v1.3.7-beta25 Apr 2026 pre-releaseNothing published for this version
-
v1.3.6-beta20 Apr 2026 pre-releaseNothing published for this version
-
v1.3.5-beta18 Apr 2026 pre-releaseNothing published for this version
-
v1.3.4-beta11 Apr 2026 pre-releaseNothing published for this version
-
v1.3.3-stable18 May 2026 pre-releaseNothing published for this version
-
v1.3.3-beta02 Apr 2026 pre-releaseNothing published for this version
-
v1.3.2-stable14 May 2026 pre-releaseNothing published for this version
-
v1.3.2-beta21 Mar 2026 pre-releaseRelease notes
Open source →Security:
- Patched Username Enumeration via Authentication Timing Side-Channel GHSA-7789-65hx-f26w
New Features:
- Option in settings
userDefaults.preferEditorForMarkdownto prefer editor first for Markdown files (#2136) - Copy to clipboard button for code blocks in Markdown Viewer (#2160)
- Add "Last modified" filter in search dialog (#2157)
Notes:
- docs preview for text and pdf has a 2 second timeout. If it hangs for whatever reason, the maximum time would be 2 seconds. (#2105) (#2114)
- Downloading multiple files streams the archive creation rather than using cacheDir -- thanks @janakoram (#2125) (#2130)
server.maxArchiveSizeGBnow defaults to 20 (GB) and only applies to archive/unarchive actions (not downloads).- browser download progress bar will no longer show for archive downloads. this is the main drawback to the streaming approach.
- should allow for much higher parallel download support and lower cleanup maintenenance.
- [docker] ffmpeg version upgraded to 8.1
- remote ip in logs now prefers
X-Forwarded-Forif it exists, thenX-Real-IP, then lastly the standard RemoteAddr. Useful when running behind a proxy to log the public IP of each request. (#2110) - changed loading spinner style to be more compatible with safari browsers.
BugFixes:
- Wrong username in share settings (#2147) (#2148)
- [OnlyOffice] Error when saving a file under a user scope #2133
- Cannot edit shared file in OnlyOffice #2143
- PWA install button disappeared (#2086)
- Deleting a root folder was possible #2128
- PUT resource api errors if action against a folder (#2153)
- LDAP authentication issue if a password caontains @ symbol (#2154)
- Share banner seems to be not working for custom urls (#2120)
-
v1.3.1-stable01 May 2026 pre-releaseNothing published for this version
-
v1.3.1-beta07 Mar 2026 pre-releaseRelease notes
Open source →Security:
- Patched Stored XSS in public share page via unsanitized share metadata (text/template misuse) GHSA-r633-fcgp-m532
- Patched Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info GHSA-525j-95gf-766f
New Features:
- More user options for settings (#2072) (#2067):
- Option to disable thumbnails
userDefaults.preview.audioanduserDefaults.preview.modelsfor Audio and 3D Models. - Option to disable files in the Tree navigation
userDefaults.hideFilesInTree - Option to disable source files deletion when creating/extracting archives.
userDefaults.deleteAfterArchive
- Option to disable thumbnails
Notes:
- Share icon does not show in share listing or for shares for other users.
- File Size Analyzer tool max items increased from 100 to 200.
- changed symlink detection logic.
BugFixes:
- 405 response code error on Webdav in 1.3.0-beta (#2054)
- Motion Preview setting not saving when changed in profile settings.
- Context menu on tools not working.
-
v1.3.0-stable20 Apr 2026 pre-releaseNothing published for this version
-
v1.3.0-beta27 Feb 2026 pre-releaseRelease notes
Open source →Note: a potentially breaking change for docker users: \the default user is now "filebrowser" 1000:1000 instead of root.
New Features:
- New Sidebar Features
- Sidebar tree navigation (#2006) (#350)
- Source usage to be customized to show os-reported values rather than calculated. This can be changed per source by editing the source link in the sidebar. (#1266) (#982)
- Archive/Unarchive actions in UI (#1252) (#335) (#1569)
- new api to archive/unarchive files on the server
- requires
createuser permissions - archiving actions respect
server.maxArchiveSize
- Added share icon to items that are shared (#1420)
- Authentication enhancements
- LDAP login support with OIDC feature parity. (#591)
- userGroup for OIDC and LDAP, only users in a group will get access. (#1964)
- Add JWT token authentication support (#1364)
- Enhanced thumbnail and item previews
- Added ability to show "motion preview" for folders with multiple child items that have previews. cycles through the first 4 images.
- support for reading embedded images from raw image or heic/heif files (#215)
- reorganized and simplified thumbnail settings in profile settings (#1968)
- removed
highQualitythumbnail option which only affected gallery view. Now its always enabled. - improved caching for unsupported images, the same file won't be attempted again with the same modtime.
- supports 3d model previews.
- FileWatcher also supports watching directories
- Support previews for 3D model files (STL, OBJ, 3MF, etc.) (#1273)
- supported formats via threejs: GLTF, GLB, OBJ, STL, PLY, DAE (Collada), 3MF, 3DS, USDZ, USD, USDA, USDC, AMF, VRML, WRL, VTK, VTP, PCD, XYZ, VOX, KMZ
- supports animations (for formats that contain them)
- supports embedded textures, external neighboring file textures, or textures in
/texturessubdirectory
- Enhanced prompts
- All prompts have a taskbar with a close button
- Prompts can be freely moved by dragging taskbar
- Prompt styling has been updated
- Clicking outside of prompts no longer automatically closes them.
- add webdav support (#209) -- thanks to @reddac for (#1764)
- see docs on how to use
- requires api an un-customized api token as password
- respects access rules
- requires download permission to view and modify/create/delete permission to modify.
Notes:
- Docker images default to
filebrowseruser instead of root - reorganized api routes
- consolidated tags for swagger to be more accurately grouped
- tools are all behind
/api/toolsroutes /api/rawis deprecated (but functional). The/api/resources/downloadroute will be used instead./api/previewhas been removed and replaced with/api/resources/preview/api/onlyofficehave been replaced with/api/office/api/shareshas been moved to/api/share/list/api/auth/tokenshas been moved to/api/auth/token/listand/api/auth/tokenadded to get specific token infoPUT /api/tokenhas been moved toPOST /api/token/public/api/shareinfohas been moved to/public/api/share/infoPOST /resources/bulk/deleteapi has been moved toDELETE /resources/bulk(#1984)
BugFixes:
- Long folder names get cut off at top navigation bar (#1934)
- New Sidebar Features
-
v1.2.7-beta23 Feb 2026 pre-releaseRelease notes
Open source →BugFixes:
- head > title > infinitely duplicating titles (#2016)
- Proxy auth not working with Nginx, stuck at logo (#2013)
-
v1.2.6-beta19 Feb 2026 pre-releaseRelease notes
Open source →Security:
- resolves https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-8vrh-3pm2-v4v6
-
v1.2.5-beta.0.20260222013023-c51b0ee9738f22 Feb 2026 pre-releaseNothing published for this version
-
v1.2.5-beta19 Feb 2026 pre-releaseRelease notes
Open source →Notes:
- Dependency Updates for frontend and backend packages
- Upgrade to go 1.26
- file list prompt interaction behavior, single-click always selects, double-click navigates. (#1911)
BugFixes:
- .ssa and .ass subtitle files get their styling removed during conversion (#1933)
- custom icons issue
- new database message for noauth (#1935)
-
v1.2.4-stable01 Apr 2026 pre-releaseNothing published for this version
-
v1.2.4-beta13 Feb 2026 pre-releaseRelease notes
Open source →Notes:
- Changed
/api/media/subtitlesapi endpoint to better support subtitles. - Correcting some errors in French language (#1947)
- add Dutch
nl.jsonfor frontend i18n -- thanks @Stephan-P (#1957) - share banner and icon images automatically serve a scaled down 1024x1024
BugFixes:
- Can't access directories with space (and possibly other special characters) when browsing a public link share (#1956)
- External ASS subtitles are not usable in web preview (#1933)
- Filename blocking rename/move (#1950)
- enforcedOtp: true blocks all user settings updates with HTTP 400 (#1962)
- Share favicon URL not showing up and Share description causing endless loading (#1911)
- folder sizes not updated for changes to filesystem outside of filebrowser (#1974)
- Changed
-
v1.2.3-stable21 Mar 2026 pre-releaseNothing published for this version
-
v1.2.3-beta05 Feb 2026 pre-releaseRelease notes
Open source →Notes:
- Removed upload api behavior to assume paths ending in "/" are folders, strictly uses isDir query param
- renamed public upload api query param from
targetPathtopath. see swagger docs.
BugFixes:
- fix stuck motion preview popup window issue
- Chunked uploads ignore User Scope and are saved to Source Root (#1894)
- share delete with user scope issue
- fix favicon pwa icon, having the PWA respect the favicon/loginIcon (#1899)
- delete prompt icons show image previews
-
v1.2.2-stable07 Mar 2026 pre-releaseRelease notes
Open source →Security:
- Patched Stored XSS in public share page via unsanitized share metadata (text/template misuse)
New Features:
- "Divider" option in sidebar links to add a text or divider between links ()
- shares offer a "go to source Location" sidebar link and button when editing a share.
Notes:
- Share edit/delete permissions are scoped to the user's shares rather than global (#2050)
BugFixes:
- fixed the requirement that the database path needed to be set in the config file, now it loads
FILEBROWSER_DATABASEvalue by default, fallback to config file property. - Error downloading zipped directory: no such file or directory (users with scope) #2015
-
v1.2.2-beta03 Feb 2026 pre-releaseRelease notes
Open source →New Features:
- Resizable sidebar (#1896)
- OIDC Authentication: Change Button Text via
frontend.oidcLoginButtonText(#1708) - improved favicon processing (#1899)
- supports more formats
- supports larger images
- automatcially generates multiple favicon sizes on startup for non-svg images. Custom svg favicons need a companion *.png to exist broad compatibilty
- Enhanced media playback: Ability to control the queue from your device's lock screen and notification panel - Will also show metadata of the current playing media if available (#1917)
Notes:
- Better text file content detection (#1726)
- More url encoding changes for API which should make things more consistent. Open issues if you see path/source not found errors.
- adjustments to the startup behavior for sqlite index for reusing the previous database on startup
- CTRL + B disables sticky sidebar forever (#1869)
- added context menu back to duplicate finder
- Sharing a link for uploads - folder/file access and UX polishing (#1902)
- improved listing view and scrolling performance
- improved image viewer which will utilize recent thumbnails as a placeholder when loading the full image.
- Small reorganization of "Share" settings to make the popup clear (#1826)
BugFixes:
- Added docker default
FILEBROWSER_CONFIG="/home/filebrowser/data/config.yaml"back -- mistakenly removed. see https://filebrowserquantum.com/en/docs/getting-started/config/#3-default-locations. (#1891) - Fix brand text in login screen (#1898)
- Sidebar links cointains urls with 2x repeated source name (#1847)
- 2 factor auth getting overwritten if you edit the auth from admin (#1819)
- New created user's files are listing error, Probably related with language setting. (#1565)
- thumbnail generation cpu/memory and concurrency bug.
- added 75MB filesize limit for image previews
- optimized concurrency for large vs small images
-
v1.2.1-stable.0.20260807212525-29f9055db96d07 Aug 2026 pre-releaseNothing published for this version
-
v1.2.1-stable.0.20260807185336-8c5c92bef05907 Aug 2026 pre-releaseNothing published for this version
-
v1.2.1-stable.0.20260802173944-b6c9cc97625002 Aug 2026 pre-releaseNothing published for this version
-
v1.2.1-stable.0.20260718010928-9503b532e1a518 Jul 2026 pre-releaseNothing published for this version
-
v1.2.1-stable.0.20260713165151-da085bca696a13 Jul 2026 pre-releaseNothing published for this version
-
v1.2.1-stable.0.20260705131828-64250ffff07605 Jul 2026 pre-releaseNothing published for this version
-
v1.2.1-stable.0.20260623151823-0bc8889c002b23 Jun 2026 pre-releaseNothing published for this version
-
v1.2.1-stable.0.20260619161757-6eaead073a6219 Jun 2026 pre-releaseNothing published for this version
-
v1.2.1-stable.0.20260611155201-826b060bb10111 Jun 2026 pre-releaseNothing published for this version
-
v1.2.1-stable.0.20260610173610-21dfc6169ea810 Jun 2026 pre-releaseNothing published for this version
-
v1.2.1-stable.0.20260609194804-4708faec5f2809 Jun 2026 pre-releaseNothing published for this version
-
v1.2.1-stable.0.20260522161427-fa5abc8c67f322 May 2026 pre-releaseNothing published for this version