CVE-2026-54088 is a command injection vulnerability in File Browser affecting versions prior to 2.63.6. The flaw is in the Go backend implementation of Hook Authentication, specifically the HookAuth.RunCommand logic in auth/hook.go. When Hook Authentication is enabled, File Browser allows an administrator-configured external command to validate logins. In vulnerable versions, user-supplied username and password values from the login request are interpolated into the configured command arguments using os.Expand without sanitization. If the configured hook invokes a shell interpreter, shell metacharacters embedded in the username or password can be interpreted as additional commands, resulting in arbitrary operating system command execution before authentication completes. The issue was fixed in 2.63.6 by removing the unsafe argument expansion behavior and passing credentials to the child process through environment variables instead.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact, self-contained proof-of-concept for CVE-2026-54088, a pre-authentication OS command injection vulnerability in File Browser Hook Authentication affecting File Browser versions <= 2.63.5. The repo contains 5 files: a README with vulnerability details and usage instructions, a Python exploit (`exploit.py`), a Docker Compose lab environment (`docker-compose.yml`), and a shell initialization script (`scripts/init-filebrowser.sh`) that configures File Browser in a deliberately vulnerable state. The main exploit logic is in `exploit.py`. It accepts a target URL, command, and password, then sends a single HTTP POST request with JSON to `/api/login`. The `username` field is crafted as `<command>; echo hook.action=block`, exploiting the vulnerable hook-auth behavior where attacker-controlled credentials are expanded into the configured shell command. This yields unauthenticated remote command execution before authentication succeeds or fails. The script handles expected HTTP responses (401/403/200) and suggests verifying side effects, especially when using the default `touch /tmp/fb_hook_auth_pwned` payload. The Docker lab is designed to reproduce the issue reliably. `scripts/init-filebrowser.sh` initializes File Browser and sets `--auth.method hook` with `--auth.command 'sh -c $USERNAME'`, which is the unsafe configuration required for exploitation. `docker-compose.yml` runs File Browser v2.63.5, exposes it on host port 8080, and persists the database and served files via mounted directories. Overall, this is a real exploit PoC rather than a detector. It demonstrates a web/network attack vector against the File Browser login endpoint and provides operational command-execution capability with a basic hardcoded payload pattern.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.