Rate-limit Bypass in FileCodeBox Affects Users' Privacy and Security
CVE-2026-64619

8.7HIGH

Key Information:

Vendor

Vastsa

Vendor
CVE Published:
20 July 2026

What is CVE-2026-64619?

FileCodeBox prior to version 2.4 is susceptible to a rate-limit bypass vulnerability within the IPRateLimit class. This issue allows attackers to bypass request throttling mechanisms by inserting manipulated X-Real-IP and X-Forwarded-For headers. The lack of validation of trusted reverse proxy origins means that attackers can deploy unique spoofed IP addresses with every request. Consequently, this enables them to enumerate potential share codes and access other users' files without any form of authentication, posing a significant threat to user privacy and data integrity.

Affected Version(s)

FileCodeBox 0 < 2.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.