CVE-2026-34529 is a Stored Cross-Site Scripting (XSS) vulnerability found in File Browser versions prior to 2.62.2, specifically within its EPUB preview function. An attacker can embed malicious JavaScript into a crafted EPUB file, which then executes in a victim's browser when previewed. This high-severity flaw (CVSS 7.6) requires low privileges and user interaction, potentially leading to high confidentiality impact. There is no evidence of active exploitation, public exploit code, or significant community attention. Organizations using File Browser are advised to upgrade to version 2.62.2 or later to remediate this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.62.2CPE matchmatch criteria | cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.