Command Execution Vulnerability in File Browser by Filebrowser
CVE-2025-52904
What is CVE-2025-52904?
The File Browser application, in version 2.32.0, presents a significant security concern due to its command execution feature, which permits the execution of shell commands outside the restricted user scope. This vulnerability enables unauthorized read and write access to sensitive server files, creating opportunities for potential exploitation. Users are urged to disable the command execution capability as a precautionary measure. For heightened security, it is advisable to employ a distroless container image when operationalizing the File Browser, particularly for setups where command execution is unnecessary. A patch has been made available to disable this feature by default, clarifying its opt-in nature, while comprehensive documentation updates advise users about the risks associated with enabling this feature.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
filebrowser <= 2.35.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
