Description
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the EPUB preview function in File Browser is vulnerable to Stored Cross-Site Scripting (XSS). JavaScript embedded in a crafted EPUB file executes in the victim's browser when they preview the file. This issue has been patched in version 2.62.2.
Published: 2026-04-01
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross-site Scripting enabling client‑side code execution when previewing EPUB files
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows an attacker to embed malicious JavaScript within an EPUB file. When a user previews the file in File Browser, the code runs in the victim’s browser. This stored XSS can lead to cookie theft, session hijacking, defacement, or any other payload that the rogue script can perform within the context of the victim. The weakness is a classic input validation flaw that corresponds to a stored cross‑site scripting (CWE‑79).

Affected Systems

File Browser installations of version 2.62.1 and earlier are affected. The issue exists in any deployment that uses the EPUB preview feature and has not applied the fix released in 2.62.2. No other products are known to be impacted.

Risk and Exploitability

The CVSS base score of 7.6 indicates high impact, while the EPSS score of less than 1% signals that exploitation is currently unlikely. The vulnerability is not in the CISA KEV list, so it is not a known exploited issue. Attackers would need to upload a malicious EPUB through the user interface and then lure a target—whether an administrative user or a general user—to view the file. Once viewed, the script executes under the context of the browser session, giving the attacker the same rights as the user. Because the script runs client‑side, no privileged server access is required, which lowers the threshold for exploitation, but the lack of automatic exploitation detection keeps the risk moderate to high for organizations that expose the preview function to untrusted users.

Generated by OpenCVE AI on April 7, 2026 at 01:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade File Browser to version 2.62.2 or later.
  • If an upgrade is not immediately feasible, disable the EPUB preview feature or block the upload of EPUB files from untrusted sources.
  • Implement a strict Content Security Policy to restrict script execution from uploaded files.
  • Monitor the file repository for anomalous EPUB uploads and review any unauthorized changes.

Generated by OpenCVE AI on April 7, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5vpr-4fgw-f69h File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file
History

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Filebrowser
Filebrowser filebrowser
Vendors & Products Filebrowser
Filebrowser filebrowser
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the EPUB preview function in File Browser is vulnerable to Stored Cross-Site Scripting (XSS). JavaScript embedded in a crafted EPUB file executes in the victim's browser when they preview the file. This issue has been patched in version 2.62.2.
Title File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Filebrowser Filebrowser
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-04-02T15:41:27.662Z

Reserved: 2026-03-30T16:03:31.048Z

Link: CVE-2026-34529

cve-icon Vulnrichment

Updated: 2026-04-02T15:40:59.163Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-01T21:17:00.830

Modified: 2026-04-06T20:39:47.500

Link: CVE-2026-34529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-07T08:07:29Z

Weaknesses