FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling of browser-renderable user uploads when served through the sharing and download endpoints. An attacker who can get a crafted SVG (primary) or HTML (secondary) file stored in a FileRise instance can cause JavaScript execution when a victim opens a generated share link (and in some cases via the direct download endpoint). This impacts share links (`/api/file/share.php`) and direct file access / download path (`/api/file/download.php`), depending on browser/content-type behavior. Version 2.7.1 fixes the issue.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 02 Jan 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:filerise:filerise:*:*:*:*:*:*:*:*

Wed, 17 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Filerise
Filerise filerise
Vendors & Products Filerise
Filerise filerise

Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
Description FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling of browser-renderable user uploads when served through the sharing and download endpoints. An attacker who can get a crafted SVG (primary) or HTML (secondary) file stored in a FileRise instance can cause JavaScript execution when a victim opens a generated share link (and in some cases via the direct download endpoint). This impacts share links (`/api/file/share.php`) and direct file access / download path (`/api/file/download.php`), depending on browser/content-type behavior. Version 2.7.1 fixes the issue.
Title FileRise vulnerable to Cross-Site Scripting (XSS) in SVG File Handling
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-16T21:38:03.188Z

Reserved: 2025-12-15T16:16:22.744Z

Link: CVE-2025-68116

cve-icon Vulnrichment

Updated: 2025-12-16T21:37:59.611Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-16T17:16:11.100

Modified: 2026-01-02T16:48:47.757

Link: CVE-2025-68116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-17T14:29:02Z

Weaknesses