Description
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.
Published: 2025-07-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21540 File Browser’s insecure JWT handling can lead to session replay attacks after logout
Github GHSA Github GHSA GHSA-7xwp-2cpp-p8r7 File Browser’s insecure JWT handling can lead to session replay attacks after logout
History

Tue, 05 Aug 2025 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:filebrowser:filebrowser:2.39.0:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00062}


Tue, 15 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Description File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.
Title FileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logout
Weaknesses CWE-305
CWE-385
CWE-613
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Filebrowser Filebrowser
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-07-15T18:37:40.098Z

Reserved: 2025-07-09T14:14:52.530Z

Link: CVE-2025-53826

cve-icon Vulnrichment

Updated: 2025-07-15T18:37:28.657Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-15T18:15:24.127

Modified: 2025-08-05T18:26:27.243

Link: CVE-2025-53826

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-16T21:35:23Z

Weaknesses