Floragasse 7 – 5th floor, 1040 Vienna
Subscribe to our Newsletter

News

SBA Security Advisory – Filebrowser Password Protection of Links Bypassable (CVE-2025-52996)

Vulnerability Overview

Files managed by Filebrowser can be shared with a link to external persons. While the application allows protecting those links with a password, the implementation is error-prone, making an incidental unprotected sharing of a file possible.

  • Type of Vulnerability: Authentication Bypass
  • Fixed in Version: Not yet
  • CVE ID: CVE-2025-52996
  • CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
  • CVSS Base Score: 3.1 (Low)

Recommended Countermeasure

We recommend to update to Filebrowser version 2.34.2 or later, which partially fixes the issue, and follow the GitHub issue #5239 for further fixes.

Links

Full Security Advisory

Credits

Mathias Tausig (SBA Research)