SCA: security update for github.com/filebrowser/filebrowser/v2 (GHSA-7526-j432-6ppp)

high Tenable Self-Hosted Container Security Plugin ID 440005

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files
within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 ("self-registered users don't get
execute perms") stripped Execute permission and Commands from users created via the signup handler. The
same fix was not applied to the proxy auth handler. Users auto-created on first successful proxy-auth
login are granted execution capabilities from global defaults, even though the signup path was explicitly
changed to prevent execution rights from being inherited by automatically provisioned accounts. This
vulnerability is fixed in 2.63.1. (CVE-2026-35607)

Solution

Update the github.com/filebrowser/filebrowser/v2 library and its related packages to version 2.63.1 or later.

See Also

https://github.com/advisories/GHSA-7526-j432-6ppp

Plugin Details

Severity: High

ID: 440005

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 4/8/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.95

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-35607

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/8/2026

Vulnerability Publication Date: 4/7/2026

Reference Information

CVE: CVE-2026-35607

cwe: CWE-269