File Access Permission Weakness in File Browser by File Browser
CVE-2025-52900

5.5MEDIUM

Key Information:

Vendor
CVE Published:
26 June 2025

What is CVE-2025-52900?

File Browser exposes a critical weakness by failing to explicitly set file access permissions for uploaded or created files. In standard configurations prior to version 2.33.7, this oversight allows all files managed by File Browser to be accessible to any operating system account. This situation poses a serious risk, especially on unhardended servers, as it could lead to unauthorized access of sensitive information stored within the File Browser. Version 2.33.7 addresses these concerns by implementing proper permission settings, thus enhancing overall security.

Affected Version(s)

filebrowser < 2.33.7

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52900 : File Access Permission Weakness in File Browser by File Browser