blob: 1c25e529015a9f5591e8890dd197a9264bf16d06 [file] [log] [blame]
id: GO-2025-3794
modules:
- module: github.com/filebrowser/filebrowser
unsupported_versions:
- last_affected: 1.11.0
vulnerable_at: 1.11.0
- module: github.com/filebrowser/filebrowser/v2
versions:
- fixed: 2.33.9
vulnerable_at: 2.33.8
summary: File Browser allows sensitive data to be transferred in URL in github.com/filebrowser/filebrowser
cves:
- CVE-2025-52901
ghsas:
- GHSA-rmwh-g367-mj4x
references:
- advisory: https://github.com/filebrowser/filebrowser/security/advisories/GHSA-rmwh-g367-mj4x
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-52901
- fix: https://github.com/filebrowser/filebrowser/commit/d5b39a14fd3fc0d1c364116b41289484df7c27b2
- web: https://github.com/filebrowser/filebrowser/releases/tag/v2.33.9
source:
id: GHSA-rmwh-g367-mj4x
created: 2025-07-21T16:57:25.996506512Z
review_status: UNREVIEWED