Rate-limit Bypass in FileCodeBox Affects Users' Privacy and Security
CVE-2026-64619
8.7HIGH
What is CVE-2026-64619?
FileCodeBox prior to version 2.4 is susceptible to a rate-limit bypass vulnerability within the IPRateLimit class. This issue allows attackers to bypass request throttling mechanisms by inserting manipulated X-Real-IP and X-Forwarded-For headers. The lack of validation of trusted reverse proxy origins means that attackers can deploy unique spoofed IP addresses with every request. Consequently, this enables them to enumerate potential share codes and access other users' files without any form of authentication, posing a significant threat to user privacy and data integrity.
Affected Version(s)
FileCodeBox 0 < 2.4
