File Access Permission Weakness in File Browser by File Browser
CVE-2025-52900
What is CVE-2025-52900?
File Browser exposes a critical weakness by failing to explicitly set file access permissions for uploaded or created files. In standard configurations prior to version 2.33.7, this oversight allows all files managed by File Browser to be accessible to any operating system account. This situation poses a serious risk, especially on unhardended servers, as it could lead to unauthorized access of sensitive information stored within the File Browser. Version 2.33.7 addresses these concerns by implementing proper permission settings, thus enhancing overall security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
filebrowser < 2.33.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
