CVE-2025-53826 Information
Jul 16, 2025
cve
Description
File Browser provides a file managing interface within a specified directory and it can be used to upload delete preview rename and edit files. In version 2.39.0 File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication no known patches exist.
Reference
https://github.com/filebrowser/filebrowser/issues/5216 https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7xwp-2cpp-p8r7 https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7xwp-2cpp-p8r7
Related CNNVD
CNNVD-202507-2058 (Published: 2025-07-15)
Share on: