SBA Security Advisory – Filebrowser Sensitive Data Transferred in URL (CVE-2025-52901)
Vulnerability Overview
URLs that are accessed by a user are commonly logged in many locations, both server- and client-side. It is thus good practice to never transmit any secret information as part of a URL. Filebrowser violates this practice, since access tokens are used as GET parameters.
- Type of Vulnerability: Information Disclosure
- Fixed in Version: 2.33.9
- CVE ID: CVE-2025-52901
- CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- CVSS Base Score: 4.5 (Medium)
Recommended Countermeasure
We recommend to update to Filebrowser to version 2.33.9 or later.
Links
Credits
Mathias Tausig (SBA Research)