GHSA-32pr-94pq-34pjHighCVSS 6.8

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy...

Published
August 13, 2026
Last Modified
August 13, 2026

🔗 CVE IDs covered (1)

📋 Description

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the renewal endpoint.

🔗 References (5)