{"schema_version":1,"title":"github.com/filebrowser/filebrowser (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in github.com/filebrowser/filebrowser (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-54097, was published on 25 June 2026.","url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser","json_url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":12,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":7},"latest":[{"cve":"CVE-2026-54097","cvss":4,"epss":0.0045,"slug":"cve-2026-54097-file-browser-authorization-bypass-in-share-link-deletion","title":"File Browser authorization bypass in share-link deletion","severity":"high","exploited":false,"published_at":"2026-06-25T19:16:41.753+00:00","url":"https://junglewise.ai/threats/cve-2026-54097-file-browser-authorization-bypass-in-share-link-deletion"},{"cve":"CVE-2026-54096","cvss":8.4,"epss":0.0018,"slug":"cve-2026-54096-file-browser-improper-authorization-via-pre-created-public-shares","title":"File Browser improper authorization via pre-created public shares","severity":"high","exploited":false,"published_at":"2026-06-25T19:16:41.62+00:00","url":"https://junglewise.ai/threats/cve-2026-54096-file-browser-improper-authorization-via-pre-created-public-shares"},{"cve":"CVE-2026-54094","cvss":7.5,"epss":0.005,"slug":"cve-2026-54094-file-browser-symlink-following-scope-bypass","title":"File Browser symlink following scope bypass","severity":"high","exploited":false,"published_at":"2026-06-25T19:16:41.49+00:00","url":"https://junglewise.ai/threats/cve-2026-54094-file-browser-symlink-following-scope-bypass"},{"cve":"CVE-2026-54093","cvss":4,"epss":0.0019,"slug":"cve-2026-54093-file-browser-path-traversal-in-archive-download-via-backslash","title":"File Browser path traversal in archive download via backslash separators","severity":"medium","exploited":false,"published_at":"2026-06-25T19:16:41.36+00:00","url":"https://junglewise.ai/threats/cve-2026-54093-file-browser-path-traversal-in-archive-download-via-backslash"},{"cve":"CVE-2026-54092","cvss":6.5,"epss":0.0004,"slug":"cve-2026-54092-file-browser-denial-of-service-via-large-password-in-login-api","title":"File Browser denial of service via large password in login API","severity":"medium","exploited":false,"published_at":"2026-06-25T19:16:41.23+00:00","url":"https://junglewise.ai/threats/cve-2026-54092-file-browser-denial-of-service-via-large-password-in-login-api"},{"cve":"CVE-2026-54091","cvss":7.5,"epss":0.0052,"slug":"cve-2026-54091-file-browser-incorrect-authorization-in-public-directory-shares","title":"File Browser incorrect authorization in public directory shares","severity":"high","exploited":false,"published_at":"2026-06-25T19:16:41.103+00:00","url":"https://junglewise.ai/threats/cve-2026-54091-file-browser-incorrect-authorization-in-public-directory-shares"},{"cve":"CVE-2026-23849","cvss":3.1,"epss":0.0049,"slug":"cve-2026-23849-file-browser-vulnerable-to-username-enumeration-via-timing-attack","title":"File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login","severity":"low","exploited":false,"published_at":"2026-01-21T01:02:17+00:00","url":"https://junglewise.ai/threats/cve-2026-23849-file-browser-vulnerable-to-username-enumeration-via-timing-attack"},{"cve":"CVE-2025-53826","cvss":4,"epss":0.005,"slug":"cve-2025-53826-file-browser-s-insecure-jwt-handling-can-lead-to-session-replay","title":"File Browser’s insecure JWT handling can lead to session replay attacks after logout","severity":"medium","exploited":false,"published_at":"2025-07-16T14:09:28+00:00","url":"https://junglewise.ai/threats/cve-2025-53826-file-browser-s-insecure-jwt-handling-can-lead-to-session-replay"},{"cve":"CVE-2025-52997","cvss":3.1,"epss":0.0052,"slug":"cve-2025-52997-file-browser-vulnerable-to-insecure-password-handling","title":"File Browser vulnerable to insecure password handling","severity":"low","exploited":false,"published_at":"2025-06-30T17:50:01+00:00","url":"https://junglewise.ai/threats/cve-2025-52997-file-browser-vulnerable-to-insecure-password-handling"},{"cve":"CVE-2025-52996","cvss":3.1,"epss":0.0036,"slug":"cve-2025-52996-file-browser-s-password-protection-of-links-is-bypassable","title":"File Browser's password protection of links is bypassable","severity":"low","exploited":false,"published_at":"2025-06-30T17:49:27+00:00","url":"https://junglewise.ai/threats/cve-2025-52996-file-browser-s-password-protection-of-links-is-bypassable"},{"cve":"CVE-2025-52902","cvss":3.1,"epss":0.003,"slug":"cve-2025-52902-filebrowser-allows-stored-cross-site-scripting-through-the","title":"filebrowser allows Stored Cross-Site Scripting through the Markdown preview function","severity":"low","exploited":false,"published_at":"2025-06-27T15:01:15+00:00","url":"https://junglewise.ai/threats/cve-2025-52902-filebrowser-allows-stored-cross-site-scripting-through-the"},{"cve":"CVE-2025-52900","cvss":3.1,"epss":0.0021,"slug":"cve-2025-52900-filebrowser-sets-insecure-file-permissions","title":"filebrowser Sets Insecure File Permissions","severity":"low","exploited":false,"published_at":"2025-06-27T14:55:07+00:00","url":"https://junglewise.ai/threats/cve-2025-52900-filebrowser-sets-insecure-file-permissions"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"}],"technology":{"hub":true,"name":"github.com/filebrowser/filebrowser (Go)","slug":"github-com-filebrowser-filebrowser","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://filebrowser.org/","repo_url":"https://github.com/filebrowser/filebrowser","description":"Filebrowser is a web-based file management interface that can be integrated into existing servers.","url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser"},"most_severe":[{"cve":"CVE-2026-54096","cvss":8.4,"epss":0.0018,"slug":"cve-2026-54096-file-browser-improper-authorization-via-pre-created-public-shares","title":"File Browser improper authorization via pre-created public shares","severity":"high","exploited":false,"published_at":"2026-06-25T19:16:41.62+00:00","url":"https://junglewise.ai/threats/cve-2026-54096-file-browser-improper-authorization-via-pre-created-public-shares"},{"cve":"CVE-2026-54091","cvss":7.5,"epss":0.0052,"slug":"cve-2026-54091-file-browser-incorrect-authorization-in-public-directory-shares","title":"File Browser incorrect authorization in public directory shares","severity":"high","exploited":false,"published_at":"2026-06-25T19:16:41.103+00:00","url":"https://junglewise.ai/threats/cve-2026-54091-file-browser-incorrect-authorization-in-public-directory-shares"},{"cve":"CVE-2026-54094","cvss":7.5,"epss":0.005,"slug":"cve-2026-54094-file-browser-symlink-following-scope-bypass","title":"File Browser symlink following scope bypass","severity":"high","exploited":false,"published_at":"2026-06-25T19:16:41.49+00:00","url":"https://junglewise.ai/threats/cve-2026-54094-file-browser-symlink-following-scope-bypass"},{"cve":"CVE-2026-54097","cvss":4,"epss":0.0045,"slug":"cve-2026-54097-file-browser-authorization-bypass-in-share-link-deletion","title":"File Browser authorization bypass in share-link deletion","severity":"high","exploited":false,"published_at":"2026-06-25T19:16:41.753+00:00","url":"https://junglewise.ai/threats/cve-2026-54097-file-browser-authorization-bypass-in-share-link-deletion"},{"cve":"CVE-2026-54092","cvss":6.5,"epss":0.0004,"slug":"cve-2026-54092-file-browser-denial-of-service-via-large-password-in-login-api","title":"File Browser denial of service via large password in login API","severity":"medium","exploited":false,"published_at":"2026-06-25T19:16:41.23+00:00","url":"https://junglewise.ai/threats/cve-2026-54092-file-browser-denial-of-service-via-large-password-in-login-api"},{"cve":"CVE-2025-53826","cvss":4,"epss":0.005,"slug":"cve-2025-53826-file-browser-s-insecure-jwt-handling-can-lead-to-session-replay","title":"File Browser’s insecure JWT handling can lead to session replay attacks after logout","severity":"medium","exploited":false,"published_at":"2025-07-16T14:09:28+00:00","url":"https://junglewise.ai/threats/cve-2025-53826-file-browser-s-insecure-jwt-handling-can-lead-to-session-replay"},{"cve":"CVE-2026-54093","cvss":4,"epss":0.0019,"slug":"cve-2026-54093-file-browser-path-traversal-in-archive-download-via-backslash","title":"File Browser path traversal in archive download via backslash separators","severity":"medium","exploited":false,"published_at":"2026-06-25T19:16:41.36+00:00","url":"https://junglewise.ai/threats/cve-2026-54093-file-browser-path-traversal-in-archive-download-via-backslash"},{"cve":"CVE-2025-52997","cvss":3.1,"epss":0.0052,"slug":"cve-2025-52997-file-browser-vulnerable-to-insecure-password-handling","title":"File Browser vulnerable to insecure password handling","severity":"low","exploited":false,"published_at":"2025-06-30T17:50:01+00:00","url":"https://junglewise.ai/threats/cve-2025-52997-file-browser-vulnerable-to-insecure-password-handling"},{"cve":"CVE-2026-23849","cvss":3.1,"epss":0.0049,"slug":"cve-2026-23849-file-browser-vulnerable-to-username-enumeration-via-timing-attack","title":"File Browser Vulnerable to Username Enumeration via Timing Attack in /api/login","severity":"low","exploited":false,"published_at":"2026-01-21T01:02:17+00:00","url":"https://junglewise.ai/threats/cve-2026-23849-file-browser-vulnerable-to-username-enumeration-via-timing-attack"},{"cve":"CVE-2025-52996","cvss":3.1,"epss":0.0036,"slug":"cve-2025-52996-file-browser-s-password-protection-of-links-is-bypassable","title":"File Browser's password protection of links is bypassable","severity":"low","exploited":false,"published_at":"2025-06-30T17:49:27+00:00","url":"https://junglewise.ai/threats/cve-2025-52996-file-browser-s-password-protection-of-links-is-bypassable"}],"generated_at":"2026-09-26T15:07:00.181821+00:00"}