<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:53:04 +0000</lastBuildDate>
    <item>
      <title>cnvd-2025-22698</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-22698</link>
      <description>cnvd-2025-22698</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-22698</guid>
    </item>
    <item>
      <title>EUVD-2026-247609</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-247609</link>
      <description>EUVD-2026-247609</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-247609</guid>
    </item>
    <item>
      <title>fkie_cve-2025-53826</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-53826</link>
      <description>&lt;p&gt;File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-53826</guid>
    </item>
    <item>
      <title>GHSA-7xwp-2cpp-p8r7 — File Browser’s insecure JWT handling can lead to session replay attacks after logout</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7xwp-2cpp-p8r7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser, Go: github.com/filebrowser/filebrowser/v2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. Please refer to the CWE&amp;#39;s listed in this report for further reference and system standards. In summary, the main issue is:&lt;/p&gt;
&lt;p&gt;- Tokens remain valid after logout (session replay attacks)&lt;/p&gt;
&lt;p&gt;In this report, I used docker as the documentation instruct:&lt;/p&gt;
&lt;p&gt;```
docker run \
    -v filebrowser_data:/srv \
    -v filebrowser_database:/database \
    -v filebrowser_config:/config \
    -p 8080:80 \
    filebrowser/filebrowser
```&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Issue: Tokens remain valid after logout (session replay attacks)**&lt;/p&gt;
&lt;p&gt;After logging in and receiving a JWT token, the user can explicitly &amp;#34;log out.&amp;#34; However, this action does not invalidate the issued JWT. Any captured token can be replayed post-logout until it expires naturally. The backend does not track active sessions or invalidate existing tokens on logout. Login request:&lt;/p&gt;
&lt;p&gt;```
POST /api/login HTTP/1.1
Host: machine.local:8090
Content-Length: 69&lt;/p&gt;
&lt;p&gt;{&amp;#34;username&amp;#34;:&amp;#34;admin&amp;#34;,&amp;#34;password&amp;#34;:&amp;#34;password-here&amp;#34;,&amp;#34;recaptcha&amp;#34;:&amp;#34;&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;The check found in the code `https://github.com/filebrowser/filebrowser/blob/master/http/auth.go` is not enough. There is no server-side blacklist or token invalidation on logout. Token renewal and validity only depends on expiry and user store timestamps:&lt;/p&gt;
&lt;p&gt;```
expired := !tk.VerifyExpiresAt(time.Now().Add(time.Hour), true)
updated := tk.IssuedAt != nil &amp;amp;&amp;amp; tk.IssuedAt.Unix() &amp;lt; d.store.Users.LastUpdate(tk.User.ID…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser, Go: github.com/filebrowser/filebrowser/v2&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. Please refer to the CWE&amp;#39;s listed in this report for further reference and system standards. In summary, the main issue is:&lt;/p&gt;
&lt;p&gt;- Tokens remain valid after logout (session replay attacks)&lt;/p&gt;
&lt;p&gt;In this report, I used docker as the documentation instruct:&lt;/p&gt;
&lt;p&gt;```
docker run \
    -v filebrowser_data:/srv \
    -v filebrowser_database:/database \
    -v filebrowser_config:/config \
    -p 8080:80 \
    filebrowser/filebrowser
```&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Issue: Tokens remain valid after logout (session replay attacks)**&lt;/p&gt;
&lt;p&gt;After logging in and receiving a JWT token, the user can explicitly &amp;#34;log out.&amp;#34; However, this action does not invalidate the issued JWT. Any captured token can be replayed post-logout until it expires naturally. The backend does not track active sessions or invalidate existing tokens on logout. Login request:&lt;/p&gt;
&lt;p&gt;```
POST /api/login HTTP/1.1
Host: machine.local:8090
Content-Length: 69&lt;/p&gt;
&lt;p&gt;{&amp;#34;username&amp;#34;:&amp;#34;admin&amp;#34;,&amp;#34;password&amp;#34;:&amp;#34;password-here&amp;#34;,&amp;#34;recaptcha&amp;#34;:&amp;#34;&amp;#34;}
```&lt;/p&gt;
&lt;p&gt;The check found in the code `https://github.com/filebrowser/filebrowser/blob/master/http/auth.go` is not enough. There is no server-side blacklist or token invalidation on logout. Token renewal and validity only depends on expiry and user store timestamps:&lt;/p&gt;
&lt;p&gt;```
expired := !tk.VerifyExpiresAt(time.Now().Add(time.Hour), true)
updated := tk.IssuedAt != nil &amp;amp;&amp;amp; tk.IssuedAt.Unix() &amp;lt; d.store.Users.LastUpdate(tk.User.ID…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7xwp-2cpp-p8r7</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</guid>
    </item>
  </channel>
</rss>
