CVE-2025-52996
Wolfi vulnerability analysis and mitigation

Overview

File Browser, a file managing interface that provides functionality to upload, delete, preview, rename and edit files, contains a vulnerability in versions 2.32.0 and prior. The vulnerability (CVE-2025-52996) was disclosed on June 29, 2025, and involves an error-prone implementation of password-protected links that could result in potential unprotected sharing of files (GitHub Advisory).

Technical details

The vulnerability stems from the implementation of the file sharing feature where two different links are generated: a share link and a direct download link. While the share link requires password authentication, the direct download link contains a token that bypasses the password protection. The vulnerability has been assigned a CVSS v3.1 base score of 3.1 (Low) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N, indicating network attack vector, high attack complexity, no privileges required, and user interaction required (GitHub Advisory).

Impact

The primary impact is that file owners might have a false sense of security, believing their shared files are only accessible to persons knowing the defined password. Attackers who gain access to the unprotected link can download potentially sensitive files without requiring the password (GitHub Advisory).

Mitigation and workarounds

A short-term mitigation was implemented in version 2.34.2, which removes the second link from the GUI when creating a password-protected share. However, this only defends against user errors and doesn't address the underlying issue of unprotected links remaining in various logs. A more thorough fix is being tracked through Issue #5239 (GitHub Advisory, GitHub Issue).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management