Home

Description

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.

PUBLISHED Reserved 2025-07-09 | Published 2025-07-15 | Updated 2025-07-15 | Assigner GitHub_M




HIGH: 7.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P

Problem types

CWE-305: Authentication Bypass by Primary Weakness

CWE-385: Covert Timing Channel

CWE-613: Insufficient Session Expiration

Product status

= 2.39.0
affected

References

github.com/...rowser/security/advisories/GHSA-7xwp-2cpp-p8r7 exploit

github.com/...rowser/security/advisories/GHSA-7xwp-2cpp-p8r7

github.com/filebrowser/filebrowser/issues/5216

cve.org (CVE-2025-53826)

nvd.nist.gov (CVE-2025-53826)

Download JSON