๐Ÿ” CVE Alert

CVE-2025-52904

HIGH 8.0

File Browser: Command Execution not Limited to Scope

CVSS Score
8.0
EPSS Score
1.1%
EPSS Percentile
79th

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions of the web application on the 2.x branch, all users have a scope assigned, and they only have access to the files within that scope. The Command Execution feature of Filebrowser allows the execution of shell commands which are not restricted to the scope, potentially giving an attacker read and write access to all files managed by the server. Until this issue is fixed, the maintainers recommend to completely disable `Execute commands` for all accounts. Since the command execution is an inherently dangerous feature that is not used by all deployments, it should be possible to completely disable it in the application's configuration. This feature has been disabled by default for all installations from v2.33.8 onwards, including for existent installations. To exploit this vulnerability, the instance administrator must turn on a feature and ignore all the warnings about known vulnerabilities.

CWE CWE-77
Vendor filebrowser
Product filebrowser
Published Jun 26, 2025
Last Updated Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for filebrowser filebrowser

Be the first to know when new high vulnerabilities affecting filebrowser filebrowser are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

filebrowser / filebrowser
>= 2.0.0, < 2.33.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-hc8f-m8g5-8362 github.com: https://github.com/filebrowser/filebrowser/issues/5199 github.com: https://github.com/GoogleContainerTools/distroless github.com: https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20250326-01_Filebrowser_Command_Execution_Not_Limited_To_Scope pkg.go.dev: https://pkg.go.dev/vuln/GO-2025-3793 sloonz.github.io: https://sloonz.github.io/posts/sandboxing-1