VYPR
Critical severityNVD Advisory· Published Jun 25, 2026· Updated Jun 25, 2026

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

CVE-2026-54088

Description

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication feature in File Browser allows administrators to delegate login verification to an external shell command. User-supplied credentials (username and password) are interpolated into this command string using os.Expand without sanitization. An unauthenticated remote attacker can inject shell metacharacters in the username or password field at the login screen, causing the server to execute arbitrary OS commands before any authentication takes place. This is a critical pre-authentication RCE. This vulnerability is fixed in 2.63.6.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/filebrowser/filebrowser/v2Go
< 2.63.62.63.6

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.