CVE-2025-53826
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53826.json, https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7xwp-2cpp-p8r7, https://nvd.nist.gov/vuln/detail/CVE-2025-53826, https://github.com/filebrowser/filebrowser/issues/5216
