File Browser Vulnerability in File Management Interface by FileBrowser
CVE-2025-52996

3.1LOW

Key Information:

Vendor
CVE Published:
30 June 2025

What is CVE-2025-52996?

The File Browser application features a file management interface that enables users to upload, delete, preview, rename, and edit files within specified directories. However, in versions prior to 2.32.0, the implementation of password-protected links contains significant flaws. As a result, it may lead to the inadvertent exposure of files due to insecure direct download links. These links can be unintentionally shared by users or found in various sources like browser histories or logs from proxy servers, posing a serious risk to sensitive data. Currently, no patches are available to resolve this vulnerability.

Affected Version(s)

filebrowser <= 2.32.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52996 : File Browser Vulnerability in File Management Interface by FileBrowser