# CVE-2025-53826

## Summary

- **CVE ID:** CVE-2025-53826
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-305, CWE-385, CWE-613
- **Published:** Jul 15, 2025
- **Last Modified:** Mar 13, 2026

## Description

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.

## Affected Products

- filebrowser — filebrowser (= 2.39.0)

## References

- [CNA](https://github.com/filebrowser/filebrowser/security/advisories/GHSA-7xwp-2cpp-p8r7)
- [CNA](https://github.com/filebrowser/filebrowser/issues/5216)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.50%
- **EPSS Percentile:** 41.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._