SBA Security Advisory – Filebrowser Shell Commands Can Spawn Other Commands (CVE-2025-52903)
Vulnerability Overview
The Command Execution feature of Filebrowser only allows the execution of shell command which have been predefined on a user-specific allowlist. Many tools allow the execution of arbitrary different commands, rendering this limitation void.
- Type of Vulnerability: Shell Commands Can Spawn Other Commands
- Fixed in Version: Not yet
- CVE ID: CVE-2025-52903
- CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
- CVSS Base Score: 8.0 (High)
Recommended Countermeasure
We recommend to disable the command execution feature according to the documentation (default since 2.33.8). Further fixes are tracked in the GitHub issue #5199.
Links
Credits
Mathias Tausig (SBA Research)