28,678 Entries 2,229 Sources 5 Verticals Last sync 14 minutes Live
Dashboard/ Self-hosted apps/ File Browser
Self-hosted apps

File Browser

filebrowser
v2.63.14 frisch latest release
07.06.2026

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

30 CVE(s) zuletzt, höchste Schwere: kritisch

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
gh_etagW/"a3ebd2bfd443a93ea333ca8e5143a2ef0f74f30841e67bef0ccaf024ca92abb8"
gh_checked_at2026-06-08T01:45:00.121232+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
Self-hosted apps High

File Browser, a file management application, fails to properly invalidate authentication tokens when users log out, allowing stolen tokens to continue providing unauthorized access until they naturally expire.

CVE-2025-53826
07.06.2026
CVE
Self-hosted apps Medium

File Browser doesn't check maximum password length during login, allowing attackers to send extremely long passwords that consume excessive CPU and memory during hashing, potentially crashing the service.

Advisory
07.06.2026
CVE
Self-hosted apps High

A security vulnerability in the File Browser application allows authenticated users to delete other users' shared links without authorization due to missing ownership validation checks.

CVE-2025-64523
07.06.2026
CVE
Self-hosted apps Critical

A critical vulnerability in the Go standard library used by File Browser allows HTTP request smuggling attacks through improper handling of line terminators in HTTP chunk data.

CVE-2025-22871
07.06.2026
CVE
Self-hosted apps Medium

A security vulnerability in File Browser software allows attackers to discover valid usernames by measuring login response times, as authentication takes longer for existing users than for non-existing ones.

CVE-2026-23849
07.06.2026
CVE
Self-hosted apps High

A vulnerability in File Browser allows authenticated users to bypass access restrictions by using multiple slashes in URLs, enabling them to access forbidden files.

CVE-2026-25890
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in File Browser software allows authenticated users to change passwords without providing the current password by using capitalization in API requests. This can lead to account takeover if attackers obtain valid authentication tokens.

CVE-2026-25889
07.06.2026
CVE
Self-hosted apps High

A vulnerability in File Browser allows attackers to access all sibling directories and their files through public share links for directories, instead of only the intended shared directory.

CVE-2026-28492
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in File Browser allows users without download permissions to still download files through public share links, bypassing access restrictions and enabling unauthorized data access.

CVE-2026-32761
07.06.2026
CVE
Self-hosted apps Critical

A security vulnerability in File Browser software allows authenticated users to delete arbitrary files and directories despite being explicitly denied delete permissions, by using an alternative TUS endpoint that incorrectly checks only create permissions instead of delete permissions.

CVE-2026-29188
07.06.2026
CVE
Self-hosted apps High

File Browser with proxy authentication blindly trusts HTTP headers from any attacker, allowing them to impersonate any user including admin without requiring passwords or other credentials.

Advisory
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in File Browser allows authenticated users to bypass administrator access restrictions by using path traversal sequences to copy or move files into directories that should be blocked by configured deny rules.

CVE-2026-32758
07.06.2026
CVE
Self-hosted apps Critical

File Browser allows unauthorized visitors to create administrator accounts when self-registration is enabled and default user permissions include admin rights, enabling complete control over the server and files.

CVE-2026-32760
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in File Browser allows authenticated users to trigger upload hooks unlimited times by using negative values in the Upload-Length header, causing hooks to execute with empty files and arbitrary filenames.

CVE-2026-32759
07.06.2026
CVE
Self-hosted apps High

A security vulnerability in File Browser allows unauthenticated users to self-register and inherit shell execution permissions, enabling them to run arbitrary commands on the server.

CVE-2026-34528
07.06.2026
CVE
Self-hosted apps High

File Browser contains a Stored Cross-Site Scripting vulnerability in the EPUB preview feature that allows attackers to execute malicious JavaScript code through crafted EPUB files and access user data.

CVE-2026-34529
07.06.2026
CVE
Self-hosted apps Medium

File Browser contains a Stored Cross-Site Scripting vulnerability where administrators can inject malicious JavaScript code into branding fields that then executes for all website visitors.

CVE-2026-34530
07.06.2026
CVE
Self-hosted apps High

File Browser fails to re-validate the current permissions of share creators when accessing public share links, allowing previously created links to remain accessible to unauthenticated users even after administrators revoke the creator's Share and Download permissions.

CVE-2026-35604
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in File Browser software allows authenticated users to access directories they shouldn't by exploiting how path checking only compares prefixes without considering directory boundaries.

CVE-2026-35605
07.06.2026
CVE
Self-hosted apps Medium

A vulnerability in File Browser allows users without download permission to read text files through an alternative API endpoint, even though downloading is explicitly prohibited for them.

CVE-2026-35606
07.06.2026
CVE
Self-hosted apps Medium

A security flaw in File Browser allows automatically created users through proxy authentication to unintentionally receive execution permissions and system commands, even though these rights should be explicitly granted by administrators.

CVE-2026-35607
07.06.2026
CVE
Self-hosted apps Critical

A critical security vulnerability in File Browser allows attackers to execute arbitrary system commands by injecting special characters into username or password fields during login, without requiring authentication.

Advisory
07.06.2026
CVE
Self-hosted apps High

A security vulnerability in File Browser allows attackers to execute arbitrary system commands by creating malicious filenames with shell metacharacters that get injected into hook commands without sanitization.

CVE-2026-35585
07.06.2026
CVE
Self-hosted apps High

A security vulnerability in File Browser allows attackers to access files and directories through public share URLs that the owner explicitly blocked with rules, as long as those blocked paths are located underneath the shared directory.

Advisory
07.06.2026
CVE
Self-hosted apps High

A vulnerability in File Browser allows low-privileged users to delete share links belonging to other users (including administrators) by removing files in their own directory whose path serves as a prefix in other users' link paths.

Advisory
07.06.2026
CVE
Self-hosted apps High

A security vulnerability in File Browser allows users with command execution permissions to bypass the command whitelist and execute arbitrary system commands by using shell metacharacters like semicolons or pipes.

Advisory
07.06.2026
CVE
Self-hosted apps Medium

File Browser does not invalidate existing JWT tokens when an administrator resets a user's password, allowing attackers with old tokens to continue accessing resources until natural token expiration.

Advisory
07.06.2026
CVE
Self-hosted apps High

File Browser allows users to access files outside their assigned scope through symbolic links, even though they should be restricted to their designated area. Attackers can read, overwrite, or publicly share unauthorized files through this vulnerability.

Advisory
07.06.2026
CVE
Self-hosted apps High

A vulnerability in File Browser allows authenticated users to create public shares for non-existent file paths that automatically become valid later when a file is created at that path.

Advisory
07.06.2026
CVE
Self-hosted apps Medium

A security vulnerability in File Browser allows attackers to create malicious archives that, when extracted on Windows systems, can write files outside the intended directory, leading to arbitrary file write operations.

Advisory
07.06.2026
REL
Self-hosted apps frisch

Release 2026-06-07

v2.63.14
07.06.2026
REL
Self-hosted apps frisch

Release 2026-06-06

v2.63.13
06.06.2026
REL
Self-hosted apps frisch

Release 2026-06-04

v2.63.11
04.06.2026
REL
Self-hosted apps frisch

Release 2026-06-04

v2.63.12
04.06.2026
REL
Self-hosted apps frisch

Release 2026-06-03

v2.63.6
03.06.2026
REL
Self-hosted apps frisch

Release 2026-06-03

v2.63.7
03.06.2026
REL
Self-hosted apps frisch

Release 2026-06-03

v2.63.8
03.06.2026
REL
Self-hosted apps frisch

Release 2026-06-03

v2.63.9
03.06.2026
REL
Self-hosted apps frisch

Release 2026-06-03

v2.63.10
03.06.2026
REL
Self-hosted apps bewährt

Release 2026-05-21

v2.63.5
21.05.2026
REL
Self-hosted apps bewährt

Release 2026-05-17

v2.63.4
17.05.2026
REL
Self-hosted apps bewährt

Release 2026-05-05

v2.63.3
05.05.2026
REL
Self-hosted apps bewährt

Release 2026-04-11

v2.63.2
11.04.2026
REL
Self-hosted apps bewährt

Release 2026-04-04

v2.63.0
04.04.2026
REL
Self-hosted apps bewährt

Release 2026-04-04

v2.63.1
04.04.2026
REL
Self-hosted apps bewährt

Release 2026-03-28

v2.62.2
28.03.2026
REL
Self-hosted apps bewährt

Release 2026-03-14

v2.62.0
14.03.2026
REL
Self-hosted apps bewährt

Release 2026-03-14

v2.62.1
14.03.2026
REL
Self-hosted apps bewährt

Release 2026-03-06

v2.61.2
06.03.2026
REL
Self-hosted apps bewährt

Release 2026-03-04

v2.61.1
04.03.2026
REL
Self-hosted apps bewährt

Release 2026-02-28

v2.61.0
28.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-21

v2.60.0
21.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-15

v2.59.0
15.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-14

v2.58.0
14.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-08

v2.57.1
08.02.2026
REL
Self-hosted apps bewährt

Release 2026-02-01

v2.57.0
01.02.2026
REL
Self-hosted apps bewährt

Release 2026-01-24

v2.56.0
24.01.2026
REL
Self-hosted apps bewährt

Release 2026-01-18

v2.55.0
18.01.2026
REL
Self-hosted apps bewährt

Release 2026-01-10

v2.54.0
10.01.2026
REL
Self-hosted apps bewährt

Release 2026-01-03

v2.53.1
03.01.2026
REL
Self-hosted apps bewährt

Release 2025-12-29

v2.53.0
29.12.2025