SBA Security Advisory – Filebrowser Insecure File Permissions (CVE-2025-52900)
Vulnerability Overview
The file access permissions for files uploaded to or created from Filebrowser are never explicitly set by the application. The same is true for the database used by Filebrowser. On standard servers where the umask configuration has not been hardened before, this makes all the stated files readable by any operating system account.
- Type of Vulnerability: Incorrect Default Permissions
- Fixed in Version: 2.33.7
- CVE ID: CVE-2025-52900
- CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- CVSS Base Score: 5.5 (Medium)
Recommended Countermeasure
We recommend to update to Filebrowser version 2.33.7 or later.
Links
Credits
Mathias Tausig (SBA Research)