Floragasse 7 – 5th floor, 1040 Vienna
Subscribe to our Newsletter

News

SBA Security Advisory – Filebrowser Shell Commands Can Spawn Other Commands (CVE-2025-52903)

Vulnerability Overview

The Command Execution feature of Filebrowser only allows the execution of shell command which have been predefined on a user-specific allowlist. Many tools allow the execution of arbitrary different commands, rendering this limitation void.

  • Type of Vulnerability: Shell Commands Can Spawn Other Commands
  • Fixed in Version: Not yet
  • CVE ID: CVE-2025-52903
  • CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
  • CVSS Base Score: 8.0 (High)

Recommended Countermeasure

We recommend to disable the command execution feature according to the documentation (default since 2.33.8). Further fixes are tracked in the GitHub issue #5199.

Links

Full Security Advisory

Credits

Mathias Tausig (SBA Research)