filebrowser has 24 CVEs on record between 2025 and 2026. Cadence is steady at roughly 11 per quarter. The busiest recent month was June 2026 with 7. The median CVSS is 6.8 (medium), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-22 (5) and CWE-59 (4). Most affected products: github.com/filebrowser/filebrowser/v2 (17), filebrowser (4), github.com/filebrowser/filebrowser (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 11 prev 8
Weakness classes
Products
- github.com/filebrowser/filebrowser/v2 17
- filebrowser 4
- github.com/filebrowser/filebrowser 3
Worst active — by depth score
CVE-2026-54088CriticalFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)64CVE-2026-25890High· 8.1File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL57CVE-2026-54089Critical· 9.1File Browser: Authentication Bypass via Proxy Auth Header Forgery50CVE-2026-90930Medium· 6.8File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules49CVE-2026-90928Medium· 6.5File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits48
filebrowser vulnerabilities
CVEs affecting filebrowser, newest first. Open any entry for full detail, references, and exploit status.
24 CVEsRSS
CVE-2026-90929High· 8.1File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go)
File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler does not reject a tar…
CVE-2026-90927Medium· 6.5PoCfilebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages
filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages…
CVE-2026-90930Medium· 6.8PoCFile Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules
File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-de…
CVE-2026-90928Medium· 6.5PoCFile Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits
File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request co…
CVE-2026-62684Low· 2.7File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandl…
CVE-2026-62843Medium· 6.8File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
CVE-2026-62685High· 8.1File Browser: Colliding username normalization gives two users the same home directory
File Browser: Colliding username normalization gives two users the same home directory
CVE-2026-55667High· 8.2File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
CVE-2026-55668Medium· 6.3File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
CVE-2026-54089Critical· 9.1File Browser: Authentication Bypass via Proxy Auth Header Forgery
File Browser: Authentication Bypass via Proxy Auth Header Forgery
CVE-2026-54088CriticalPoCFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
CVE-2026-54097HighFile Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
CVE-2026-54096HighFile Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
CVE-2026-54092High· 6.5File Browser has a DoS Vulnerability via Public Login API
File Browser has a DoS Vulnerability via Public Login API
CVE-2026-54094Medium· 6.8File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
CVE-2026-54093MediumFile Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
CVE-2026-54091High· 7.5File Browser has incorrect access control for public directory shares via rule path rebasing
File Browser has incorrect access control for public directory shares via rule path rebasing
CVE-2026-54090HighFile Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
CVE-2026-35607High· 8.1File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
CVE-2026-25890High· 8.1PoCFile Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL
File Browser has a Path-Based Access Control Bypass via Multiple Leading Slashes in URL
CVE-2026-23849Medium· 5.3File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login
File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login
CVE-2025-53893HighFile Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
CVE-2025-53826HighFile Browser’s insecure JWT handling can lead to session replay attacks after logout
File Browser’s insecure JWT handling can lead to session replay attacks after logout
CVE-2025-52996Low· 3.1File Browser's password protection of links is bypassable
File Browser's password protection of links is bypassable