NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #410 by repository stars
Last release today
04 Oct 2026
Ships on a steady schedule
a new release about every 1 weeks
Nearly every release is documented
notes for 15 of 15 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
391 releases · first in 2023
One column per quarter.
Nothing published for this version
Patched Username Enumeration via Authentication Timing Side-Channel GHSA-7789-65hx-f26w
Security:
New Features:
userDefaults.preferEditorForMarkdown to prefer editor first for Markdown files (#2136)Notes:
server.maxArchiveSizeGB now defaults to 20 (GB) and only applies to archive/unarchive actions (not downloads).X-Forwarded-For if it exists, then X-Real-IP, then lastly the standard RemoteAddr. Useful when running behind a proxy to log the public IP of each request. (#2110)BugFixes:
Nothing published for this version
Patched Incomplete Remediation of CVE-2026-27611: Password-Protected Share Bypass via /public/api/share/info GHSA-525j-95gf-766f
Security:
New Features:
userDefaults.preview.audio and userDefaults.preview.models for Audio and 3D Models.userDefaults.hideFilesInTreeuserDefaults.deleteAfterArchiveNotes:
BugFixes:
Nothing published for this version
Note: a potentially breaking change for docker users: \the default user is now "filebrowser" 1000:1000 instead of root.
Note: a potentially breaking change for docker users: \the default user is now "filebrowser" 1000:1000 instead of root.
New Features:
create user permissionsserver.maxArchiveSizehighQuality thumbnail option which only affected gallery view. Now its always enabled./textures subdirectoryNotes:
filebrowser user instead of root/api/tools routes/api/raw is deprecated (but functional). The /api/resources/download route will be used instead./api/preview has been removed and replaced with /api/resources/preview/api/onlyoffice have been replaced with /api/office/api/shares has been moved to /api/share/list/api/auth/tokens has been moved to /api/auth/token/list and /api/auth/token added to get specific token infoPUT /api/token has been moved to POST /api/token/public/api/shareinfo has been moved to /public/api/share/infoPOST /resources/bulk/delete api has been moved to DELETE /resources/bulk (#1984)BugFixes:
head > title > infinitely duplicating titles
BugFixes:
resolves https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-8vrh-3pm2-v4v6
Security:
Nothing published for this version
Dependency Updates for frontend and backend packages
Notes:
BugFixes:
Nothing published for this version
Changed /api/media/subtitles api endpoint to better support subtitles.
Notes:
/api/media/subtitles api endpoint to better support subtitles.nl.json for frontend i18n -- thanks @Stephan-P (#1957)BugFixes:
Nothing published for this version
Removed upload api behavior to assume paths ending in "/" are folders, strictly uses isDir query param
Notes:
targetPath to path. see swagger docs.BugFixes:
Patched Stored XSS in public share page via unsanitized share metadata (text/template misuse)
Security:
New Features:
Notes:
BugFixes:
FILEBROWSER_DATABASE value by default, fallback to config file property.OIDC Authentication: Change Button Text via frontend.oidcLoginButtonText
New Features:
frontend.oidcLoginButtonText (#1708)Notes:
BugFixes:
FILEBROWSER_CONFIG="/home/filebrowser/data/config.yaml" back -- mistakenly removed. see https://filebrowserquantum.com/en/docs/getting-started/config/#3-default-locations. (#1891)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
startup icon generation order issue
BugFixes:
Global disable onlyoffice editor via "*" file option to disable all files for a specific user.
New Features:
Notes:
file query param for path instead of files with comma. See swagger for details (#1881)BugFixes:
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →