PT-2025-27473 · Unknown · Filebrowser

Mtausig

·

Published

2025-03-25

·

Updated

2025-08-04

·

CVE-2025-52995

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: File Browser versions prior to 2.33.10
Description: The issue affects the implementation of the allowlist in File Browser, allowing unauthorized execution of shell commands. The impact depends on the configured commands and installed binaries on the server or container image. Due to the lack of separation of scopes on the OS-level, an attacker could access all files managed by the application, including the File Browser database.
Recommendations: For versions prior to 2.33.10, update to version 2.33.10 to resolve the issue.

Exploit

Fix

LPE

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-08007
CVE-2025-52995
GHSA-W7QC-6GRJ-W7R8
GO-2025-3795
OPENSUSE-SU-2025:15405-1

Affected Products

Filebrowser