CVE-2026-35585 affects File Browser from version 2.0.0 through 2.33.7. The vulnerable component is the hook system, which allows administrator-defined shell commands to be executed on file events such as upload, rename, and delete. The issue arises because variable substitution for attacker-influenced values such as $FILE and $USERNAME is performed using os.Expand without sanitization before being passed to shell-based hooks. An attacker with file write-related permissions can supply a crafted filename containing shell metacharacters so that, when a configured hook is triggered, arbitrary operating system commands are executed on the server. The result is remote code execution in the security context of the File Browser process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept for CVE-2026-35585, an authenticated OS command injection vulnerability in File Browser affecting versions 2.0.0 through 2.33.1. The repo contains four files: a README with setup and exploitation steps, a remediation guide, a docker-compose file that launches a vulnerable File Browser v2.33.1 instance, and the main exploit script exploit.py. The exploit logic in exploit.py is straightforward and functional. It accepts a target URL, username, password, and arbitrary command. It creates a requests session, authenticates to the File Browser API at /api/login, extracts the returned JWT-like token from the response body, and places it in the X-Auth header. It then constructs a malicious filename using the pattern '; <command> #', URL-encodes it, and uploads content to /api/resources/{encoded_filename}. If the target has a shell-based after_upload hook configured, the filename is expanded into the shell command context and the injected command executes on the host/container. Primary exploit capability: authenticated remote code execution via malicious filename upload. This is a web/network attack against the File Browser HTTP API, but it depends on specific target-side configuration: custom command hooks must be enabled and executed through a shell such as 'sh -c', and the attacker must have valid credentials with upload rights. The provided default payload is a simple shell command that creates a file in /tmp, demonstrating code execution rather than delivering a full shell. Repository structure and purpose: README.md explains the vulnerability, vulnerable versions, Docker-based lab setup, offline hook configuration commands, exploit usage, and verification steps. SOLUTION.md documents mitigations and secure coding guidance. docker-compose.yml provisions the vulnerable environment using image filebrowser/filebrowser:v2.33.1 exposed on localhost:8080. exploit.py is the only real code artifact and the clear entry point. Overall, this is a legitimate operational PoC rather than a scanner or detection script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.