PT-2026-52536 · Unknown · Filebrowser
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
File Browser versions prior to 2.63.6
Description
The Hook Authentication feature allows administrators to delegate login verification to an external shell command. User-supplied credentials, specifically the
username and password variables, are interpolated into this command string using os.Expand without proper sanitization. An unauthenticated remote attacker can inject shell metacharacters into these fields at the login screen, leading to remote code execution (RCE) where the server executes arbitrary OS commands before authentication occurs.Recommendations
Update to version 2.63.6.
As a temporary workaround, consider disabling the Hook Authentication feature to minimize the risk of exploitation.
Exploit
Fix
RCE
Missing Authentication
OS Command Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Filebrowser