Description
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser. Version 2.33.7 contains a fix for the issue.
Published: 2025-06-26
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19201 filebrowser allows Stored Cross-Site Scripting through the Markdown preview function
Github GHSA Github GHSA GHSA-4wx8-5gm2-2j97 filebrowser allows Stored Cross-Site Scripting through the Markdown preview function
History

Thu, 10 Jul 2025 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Filebrowser
Filebrowser filebrowser
CPEs cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*
Vendors & Products Filebrowser
Filebrowser filebrowser

Thu, 26 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 15:00:00 +0000

Type Values Removed Values Added
Description File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. The Markdown preview function of File Browser prior to v2.33.7 is vulnerable to Stored Cross-Site-Scripting (XSS). Any JavaScript code that is part of a Markdown file uploaded by a user will be executed by the browser. Version 2.33.7 contains a fix for the issue.
Title File Browser has Stored Cross-Site Scripting vulnerability
Weaknesses CWE-79
CWE-80
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Filebrowser Filebrowser
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-06-26T15:01:19.861Z

Reserved: 2025-06-20T17:42:25.712Z

Link: CVE-2025-52902

cve-icon Vulnrichment

Updated: 2025-06-26T15:01:12.409Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-26T15:15:23.687

Modified: 2025-07-10T01:09:35.847

Link: CVE-2025-52902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-06T22:16:30Z

Weaknesses