Floragasse 7 – 5th floor, 1040 Vienna
Subscribe to our Newsletter

News

SBA Security Advisory – Filebrowser Stored Cross-Site Scripting (CVE-2025-52902)

Vulnerability Overview

The Markdown preview function of Filebrowser v2.32.0 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser.

  • Type of Vulnerability: Stored XSS
  • Fixed in Version: 2.33.7
  • CVE ID: CVE-2025-52902
  • CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
  • CVSS Base Score: 7.6 (High)

Recommended Countermeasure

We recommend to update to Filebrowser version 2.33.7 or later.

Links

Full Security Advisory

Credits

Mathias Tausig (SBA Research)