SBA Security Advisory – Filebrowser Stored Cross-Site Scripting (CVE-2025-52902)
Vulnerability Overview
The Markdown preview function of Filebrowser v2.32.0 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser.
- Type of Vulnerability: Stored XSS
- Fixed in Version: 2.33.7
- CVE ID: CVE-2025-52902
- CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
- CVSS Base Score: 7.6 (High)
Recommended Countermeasure
We recommend to update to Filebrowser version 2.33.7 or later.
Links
Credits
Mathias Tausig (SBA Research)