Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-53826


File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.


Published

2025-07-15T18:15:24.127

Last Modified

2025-08-05T18:26:27.243

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-305
    CWE-385
    CWE-613

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application filebrowser filebrowser 2.39.0 Yes

References