Executive brief
filebrowser is a web-based file manager and browser that allows users to upload, download, and manage files through a web interface. An authenticated attacker can send oversized WebSocket messages to the command endpoint, causing the application server to allocate excessive memory and become unresponsive, resulting in service unavailability. This can happen even if command execution is disabled or the attacker lacks permission to execute commands.
Technical details
The /api/command WebSocket handler in filebrowser through 2.63.23 fails to set a read limit on incoming WebSocket messages, allowing the handler to buffer complete messages in memory before checking authorization. The vulnerability is triggered in the commandsHandler function, which calls conn.ReadMessage() to read a full client message prior to validating either the EnableExec setting or the user's Perm.Execute permission. gorilla/websocket applies no default message size limit when SetReadLimit is not invoked, causing arbitrarily large messages to be fully buffered on the heap. An authenticated user can exploit this by sending progressively larger or concurrent WebSocket messages to exhaust server memory and trigger denial of service. The project is archived and unmaintained, with no patch available; the recommended workaround is to block /api/command at the reverse proxy level.
Affected products
- filebrowser filebrowser through 2.63.23
Timeline
- 2026-08-31: disclosed: Advisory published on GitHub
- 2026-09-14: advisory: CVE-2026-90927 published