CyberRota Analysis
AI-GeneratedFilebrowser versions up to 2.63.23 are vulnerable due to inadequate validation of named pipes in directory archive and public download handlers. This flaw allows both authenticated users and anonymous visitors with public share links to exploit the system by repeatedly requesting archives containing named pipes, potentially leading to resource exhaustion and denial of service. Organizations utilizing Filebrowser should prioritize addressing this vulnerability to prevent service disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly request archives containing named pipes to pin server goroutines and exhaust connection resources.