Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-90929High· 8.1File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler does not reject a tar…
CVE-2026-90927Medium· 6.5PoCfilebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages…
CVE-2026-90930Medium· 6.8PoCFile Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-de…
CVE-2026-90928Medium· 6.5PoCFile Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request co…
CVE-2026-62684Low· 2.7File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandl…
CVE-2026-62843Medium· 6.8File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
CVE-2026-62685High· 8.1File Browser: Colliding username normalization gives two users the same home directory
CVE-2026-55667High· 8.2File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
CVE-2026-55668Medium· 6.3File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
CVE-2026-54089Critical· 9.1File Browser: Authentication Bypass via Proxy Auth Header Forgery
CVE-2026-54088CriticalPoCFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
CVE-2026-54097HighFile Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
CVE-2026-54096HighFile Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
CVE-2026-54092High· 6.5File Browser has a DoS Vulnerability via Public Login API
CVE-2026-54094Medium· 6.8File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
CVE-2026-54093MediumFile Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
CVE-2026-54091High· 7.5File Browser has incorrect access control for public directory shares via rule path rebasing
CVE-2026-54090HighFile Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
CVE-2026-35607High· 8.1File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
CVE-2026-25890High· 8.1PoCFile Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL
CVE-2026-23849Medium· 5.3File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login
CVE-2025-53893HighFile Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
CVE-2025-53826HighFile Browser’s insecure JWT handling can lead to session replay attacks after logout
CVE-2025-52996Low· 3.1File Browser's password protection of links is bypassable
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.