SBA Security Advisory – Filebrowser Command Execution Allowlist Bypass (CVE-2025-52995)
Vulnerability Overview
The Command Execution feature of Filebrowser only allows the execution of shell commands which have been predefined on a user-specific allowlist. The implementation of this allowlist is erroneous, allowing a user to execute additional commands not permitted.
- Type of Vulnerability: Remote Code Execution
- Fixed in Version: 2.33.10
- CVE ID: CVE-2025-52995
- CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
- CVSS Base Score: 8.0 (High)
Recommended Countermeasure
We recommend to update to Filebrowser version 2.33.10 or later.
Links
Credits
Mathias Tausig (SBA Research)