SBA Security Advisory – Filebrowser Password Protection of Links Bypassable (CVE-2025-52996)
Vulnerability Overview
Files managed by Filebrowser can be shared with a link to external persons. While the application allows protecting those links with a password, the implementation is error-prone, making an incidental unprotected sharing of a file possible.
- Type of Vulnerability: Authentication Bypass
- Fixed in Version: Not yet
- CVE ID: CVE-2025-52996
- CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
- CVSS Base Score: 3.1 (Low)
Recommended Countermeasure
We recommend to update to Filebrowser version 2.34.2 or later, which partially fixes the issue, and follow the GitHub issue #5239 for further fixes.
Links
Credits
Mathias Tausig (SBA Research)