{"schema_version":"1.9.0","id":"CVE-2025-53826","published":"2025-07-15T18:12:24.289Z","modified":"2026-08-12T03:51:26.159005347Z","aliases":["GHSA-7xwp-2cpp-p8r7","GO-2025-3812"],"related":["openSUSE-SU-2025:15405-1"],"summary":"FileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logout","details":"File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/filebrowser/filebrowser","events":[{"introduced":"e6ffb653740e37118d1882edb8d71ebe6663fece"},{"last_affected":"e6ffb653740e37118d1882edb8d71ebe6663fece"}],"database_specific":{"cpe":"cpe:2.3:a:filebrowser:filebrowser:2.39.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"= 2.39.0"},{"last_affected":"= 2.39.0"},{"introduced":"2.39.0"},{"last_affected":"2.39.0"}],"source":["AFFECTED_FIELD","CPE_STRING"]}}],"versions":["2.39.0","= 2.39.0","v2.39.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53826.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53826.json"},{"type":"ADVISORY","url":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7xwp-2cpp-p8r7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53826"},{"type":"REPORT","url":"https://github.com/filebrowser/filebrowser/issues/5216"}],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-305","CWE-385","CWE-613"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53826.json"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"}]}