PT-2025-26978 · Unknown · Filebrowser

Mtausig

·

Published

2025-06-26

·

Updated

2026-03-10

·

CVE-2025-52902

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions: File Browser versions prior to 2.33.7
Description: The Markdown preview function of File Browser is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser.
Recommendations: For versions prior to 2.33.7, update to version 2.33.7 to resolve the issue. As a temporary workaround, consider disabling the Markdown preview function until the update is applied. Restrict access to uploading Markdown files to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-52902
GHSA-4WX8-5GM2-2J97
GO-2025-3784
OPENSUSE-SU-2025:15405-1

Affected Products

Filebrowser