CVE-2025-53826: Filebrowser
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.
Affected products
- Filebrowser Filebrowser: version 2.39.0 only
Published 2025-07-15. Last modified 2026-06-17.