CVE-2025-64523 Details
Description
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Versions prior to 2.45.1 have an Insecure Direct Object Reference (IDOR) vulnerability in the FileBrowser application's share deletion functionality. This vulnerability allows any authenticated user with share permissions to delete other users' shared links without authorization checks. The impact is significant as malicious actors can disrupt business operations by systematically removing shared files and links. This leads to denial of service for legitimate users, potential data loss in collaborative environments, and breach of data confidentiality agreements. In organizational settings, this could affect critical file sharing for projects, presentations, or document collaboration. Version 2.45.1 contains a fix for the issue.
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the File Browser application, specifically in versions through 2.45.0. This vulnerability resides within the share deletion feature, where authenticated users with share permissions can delete links shared by other users without proper authorization checks. The absence of these checks allows for the deletion of shared files and links, potentially disrupting business operations, causing data loss in collaborative environments, and violating data confidentiality agreements. In organizational contexts, this could hinder essential file sharing for projects, presentations, or document collaboration.
Users can update to File Browser version 2.45.1, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/filebrowser/filebrowser/security/advisories/GHSA-6cqf-cfhv-659g | CISA-ADP | ExploitVendor Advisory |
| https://github.com/filebrowser/filebrowser/commit/291223b3cefe1e50fae8f73d70464b1dc25351a4 | [email protected] | Patch |
| https://github.com/filebrowser/filebrowser/security/advisories/GHSA-6cqf-cfhv-659g | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| filebrowser filebrowser | < 2.45.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 3, 2026 | Initial Analysis | [email protected] |
| Nov 13, 2025 | CVE Modified | CISA-ADP |
| Nov 12, 2025 | New CVE Received | [email protected] |