PT-2026-30904 · Unknown · Filebrowser

·

CVE-2026-35585

·

Published

2026-04-07

·

Updated

2026-07-30

CVSS v4.0

7.5

High

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions File Browser versions 2.0.0 through 2.33.8
Description The hook system in File Browser, which executes administrator-defined shell commands during file events such as upload, rename, and delete, is susceptible to OS command injection. The issue occurs in the Runner.exec() function within the runner/runner.go file, where variable substitution for values like $FILE and $USERNAME is performed using os.Expand without proper sanitization. An authenticated attacker with file write permissions can craft a malicious filename containing shell metacharacters. When the hook fires, the server executes these characters as arbitrary OS commands, leading to Remote Code Execution (RCE). This pattern is exploitable across various hook events, including before upload, after upload, before rename, after rename, before delete, and after delete.
Recommendations Update to version 2.33.8 or later, as the hook feature is disabled by default from this version onwards. As a temporary workaround, disable the hook system or restrict the use of the Runner.exec() function until the software is updated.

Exploit

Fix

RCE

Argument Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35585
GHSA-JVPW-637P-H3PW
GO-2026-5481
OPENSUSE-SU-2026:21483-1

Affected Products

Filebrowser