HarborGuard / CVE
Back to search
HIGHCVE-2026-34529Published Modified CNA GitHub_M

CVE-2026-34529: File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the EPUB preview function in File Browser is vulnerable to Stored Cross-Site Scripting (XSS). JavaScript embedded in a crafted EPUB file executes in the victim's browser when they preview the file. This issue has been patched in version 2.62.2.

Metrics

CVSS v3.1
7.6
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • filebrowser / filebrowser
    < 2.62.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N