Floragasse 7 – 5th floor, 1040 Vienna
Subscribe to our Newsletter

News

SBA Security Advisory – Filebrowser Command Execution Allowlist Bypass (CVE-2025-52995)

Vulnerability Overview

The Command Execution feature of Filebrowser only allows the execution of shell commands which have been predefined on a user-specific allowlist. The implementation of this allowlist is erroneous, allowing a user to execute additional commands not permitted.

  • Type of Vulnerability: Remote Code Execution
  • Fixed in Version: 2.33.10
  • CVE ID: CVE-2025-52995
  • CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
  • CVSS Base Score: 8.0 (High)

Recommended Countermeasure

We recommend to update to Filebrowser version 2.33.10 or later.

Links

Full Security Advisory

Credits

Mathias Tausig (SBA Research)