๐Ÿ” CVE Alert

CVE-2025-52903

HIGH 8.0

File Browser Allows Execution of Shell Commands That Can Spawn Other Commands

CVSS Score
8.0
EPSS Score
1.3%
EPSS Percentile
80th

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions on the 2.x branch prior to 2.33.10, the Command Execution feature of File Browser only allows the execution of shell command which have been predefined on a user-specific allowlist. Many tools allow the execution of arbitrary different commands, rendering this limitation void. The concrete impact depends on the commands being granted to the attacker, but the large number of standard commands allowing the execution of subcommands makes it likely that every user having the `Execute commands` permissions can exploit this vulnerability. Everyone who can exploit it will have full code execution rights with the uid of the server process. Version 2.33.10 contains a check for whether a command is allowed when using shell.

CWE CWE-77
Vendor filebrowser
Product filebrowser
Published Jun 26, 2025
Last Updated Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for filebrowser filebrowser

Be the first to know when new high vulnerabilities affecting filebrowser filebrowser are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

filebrowser / filebrowser
>= 2.0.0, < 2.33.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-3q2w-42mv-cph4 github.com: https://github.com/filebrowser/filebrowser/issues/5199 github.com: https://github.com/filebrowser/filebrowser/commit/4d830f707fc4314741fd431e70c2ce50cd5a3108 github.com: https://github.com/GoogleContainerTools/distroless github.com: https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20250326-02_Filebrowser_Shell_Commands_Can_Spawn_Other_Commands manpages.debian.org: https://manpages.debian.org/bookworm/util-linux/prlimit.1.en.html pkg.go.dev: https://pkg.go.dev/vuln/GO-2025-3786