PT-2025-29583 · Unknown · Filebrowser

Maen08

·

Published

2025-07-15

·

Updated

2025-08-05

·

CVE-2025-53893

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions File Browser version 2.38.0
Description File Browser provides a file managing interface for managing files within a specified directory, including upload, delete, preview, rename, and edit functionalities. A denial-of-service issue exists in the file processing logic when reading a file on the /files/{file-name} endpoint. The server attempts to load the entire file content into memory during read operations without size checks or resource limits. This allows an authenticated user to upload a large file and trigger uncontrolled memory consumption on read, potentially crashing the server and making it unresponsive.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2025-53893
GHSA-7XQM-7738-642X
GO-2025-3811
OPENSUSE-SU-2025:15405-1

Affected Products

Filebrowser