FileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logout
Vulnerability Description
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53826
Credits & Attribution
No credits recorded in the NVD database.
References
More from filebrowser
View All →Affected Vendor
filebrowser
View all reports →