CVE Explorer
CVE-2026-25890
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated user can bypass the application's "Disallow" file path rules by modifying the request URL. By adding multiple slashes (e.g., //private/) to the path, the authorization check fails to match the rule, while the underlying filesystem resolves the path correctly, granting unauthorized access to restricted files. This vuln
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6c507f5d47c4de04c54dc1fc4c2681f86958a20c1c94bcc60fcd016b87cc88c4 · sha256:19546f91658185c0… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-706","description":"CWE-706: Use of Incorrectly-Resolved Name or Reference","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6c507f5d47c4de04c54dc1fc4c2681f86958a20c1c94bcc60fcd016b87cc88c4 · sha256:19546f91658185c0… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"filebrowser","vendor":"filebrowser","versions":[{"status":"affected","version":"< 2.57.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6c507f5d47c4de04c54dc1fc4c2681f86958a20c1c94bcc60fcd016b87cc88c4 · sha256:19546f91658185c0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6c507f5d47c4de04c54dc1fc4c2681f86958a20c1c94bcc60fcd016b87cc88c4 · sha256:19546f91658185c0… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6c507f5d47c4de04c54dc1fc4c2681f86958a20c1c94bcc60fcd016b87cc88c4 · sha256:19546f91658185c0… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-706","description":"CWE-706: Use of Incorrectly-Resolved Name or Reference","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6c507f5d47c4de04c54dc1fc4c2681f86958a20c1c94bcc60fcd016b87cc88c4 · sha256:19546f91658185c0… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/filebrowser/filebrowser/commit/489af403a19057f6b6b4b1dc0e48cbb26a202ef9","tags":["x_refsource_MISC"],"url":"https://github.com/filebrowser/filebrowser/commit/489af403a19057f6b6b4b1dc0e48cbb26a202ef9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6c507f5d47c4de04c54dc1fc4c2681f86958a20c1c94bcc60fcd016b87cc88c4 · sha256:19546f91658185c0… · /containers/cna/references/1
{"name":"https://github.com/filebrowser/filebrowser/releases/tag/v2.57.1","tags":["x_refsource_MISC"],"url":"https://github.com/filebrowser/filebrowser/releases/tag/v2.57.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6c507f5d47c4de04c54dc1fc4c2681f86958a20c1c94bcc60fcd016b87cc88c4 · sha256:19546f91658185c0… · /containers/cna/references/2
{"name":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-4mh3-h929-w968","tags":["x_refsource_CONFIRM"],"url":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-4mh3-h929-w968"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6c507f5d47c4de04c54dc1fc4c2681f86958a20c1c94bcc60fcd016b87cc88c4 · sha256:19546f91658185c0… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.