FileBrowser是filebrowser团队开源的一个文件管理界面,在指定的目录,它可以用来上传、删除、预览和编辑文件。 File Browser 2.33.8之前版本存在安全漏洞,该漏洞源于命令白名单仅验证用户输入的第一个令牌,但原始字符串被直接传递给shell,允许分号、管道、反引号和$()等元字符绕过白名单,可能导致任意命令执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| filebrowser | filebrowser | < 2.33.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| filebrowser | filebrowser | < 2.33.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54089 | 9.1 CRITICAL | File Browser: Authentication Bypass via Proxy Auth Header Forgery |
| CVE-2026-54096 | 8.4 HIGH | File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existe |
| CVE-2026-55667 | 8.2 HIGH | File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-followin |
| CVE-2026-54094 | 7.5 HIGH | File Browser: Symlink following lets scoped users read, overwrite, and share files outside |
| CVE-2026-54091 | 7.5 HIGH | File Browser: Incorrect access control in public directory shares via rule path rebasing |
| CVE-2026-54092 | 6.5 MEDIUM | File Browser: DoS Vulnerability on Public Login API |
| CVE-2026-54088 | File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentica | |
| CVE-2026-54093 | File Browser: Path traversal in download-as-zip/tar via Windows-style backslash separators | |
| CVE-2026-54097 | File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in De |
No comments yet