Floragasse 7 – 5th floor, 1040 Vienna
Subscribe to our Newsletter

News

SBA Security Advisory – Filebrowser Insecure File Permissions (CVE-2025-52900)

Vulnerability Overview

The file access permissions for files uploaded to or created from Filebrowser are never explicitly set by the application. The same is true for the database used by Filebrowser. On standard servers where the umask configuration has not been hardened before, this makes all the stated files readable by any operating system account.

  • Type of Vulnerability: Incorrect Default Permissions
  • Fixed in Version: 2.33.7
  • CVE ID: CVE-2025-52900
  • CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • CVSS Base Score: 5.5 (Medium)

Recommended Countermeasure

We recommend to update to Filebrowser version 2.33.7 or later.

Links

Full Security Advisory

Credits

Mathias Tausig (SBA Research)