# File Browser: Archived File Manager with Unfixed JWT and Command Execution Flaws

> A Go-based web file manager archived in September 2026 with two known security vulnerabilities that will not be patched, requiring operators to run it behind a reverse proxy and keep command execution disabled.

**filebrowser/filebrowser** — File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview and edit your files.

- Repository: https://github.com/filebrowser/filebrowser
- Stars: 35,940 · Forks: 4,108
- Language: Go
- License: Apache-2.0
- Published: 2026-08-04 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/filebrowser-filebrowser

## The project was archived on 2026-09-01 with no further releases or security fixes planned

The README displays a warning banner stating File Browser is archived on 2026-09-01 and the last planned release has already shipped. There will be no further releases, bug fixes, or security fixes. The last push to the repository occurred on 2026-07-31, and the final release v2.63.23 was published on 2026-07-27. The background blog post Goodbye File Browser, for Real This Time from July 2026 explains the decision. Anyone continuing to run File Browser must treat it as unmaintained software. The CONTRIBUTING.md documents how to build and develop the project, which remains useful to anyone forking it, but the original maintainers will not accept pull requests or issue reports for security vulnerabilities.

## Command execution runner is disabled by default but fundamentally vulnerable if re-enabled

The command execution, runner, and hooks feature is plagued with vulnerabilities across many published advisories and would need a full rewrite to be made safe. It is disabled by default; if an operator re-enables it with --disable-exec=false, the ability to run commands should be treated as equivalent to shell access on the host. The README references issue #5199 and docs/command-execution.md for background. This means any user who gains access to the command runner can execute arbitrary code on the host system with the privileges of the File Browser process. The security section explicitly advises keeping the command runner disabled and leaving it off. There is no mitigation documented for safely enabling this feature.

## JWT session tokens cannot be revoked making logout and password changes ineffective

Sessions are self-contained JWTs rather than server-side identifiers, so they cannot be revoked. This means logout, password changes, and token renewal leave previously issued tokens valid until they expire, and the same refresh token can be redeemed repeatedly. The README references issue #5216 for background. Operators must assume a leaked token is valid until expiry. There is no mechanism to force a global logout or invalidate all sessions for a compromised account. This affects any deployment where token leakage is possible, including shared hosting environments or compromised client devices. The only mitigation is setting short token expiry times, but the README does not document the default expiry or how to configure it.

## Docker deployment requires Redis for caching and runs as non-root user in a busybox image

The compose.yaml defines two services: filebrowser and redis. The filebrowser service uses image filebrowser/filebrowser:latest, maps port 8000:80, mounts a volume filebrowser:/flux/vault, and sets environment variable FB_REDIS_CACHE_URL=redis://default:filebrowser@redis:6379 with a comment to use rediss:// for SSL. The redis service runs redis:latest with a custom ACL file creating a user default with password filebrowser. The Dockerfile uses a multi-stage build: first stage alpine:3.23 fetches ca-certificates, mailcap, tini-static, and JSON.sh; second stage busybox:1.37.0-musl creates UID=1000 GID=1000 user, copies the binary and configs, and sets ENTRYPOINT [ "tini", "--", "/init.sh" ]. Volumes are declared for /srv, /config, and /database. HEALTHCHECK runs /healthcheck.sh every 5 seconds with a 3-second timeout.

## Direct internet exposure is explicitly discouraged and reverse proxy with TLS is required

The security section states: Do not expose it directly to the internet. Put it behind a reverse proxy that terminates TLS and performs its own authentication. This is not a suggestion but a requirement given the unpatched vulnerabilities. The command runner must remain disabled (it is off by default). The application should run unprivileged, inside a container, with only the directory intended to serve mounted into it. The Dockerfile enforces non-root execution with USER user and UID=1000 GID=1000. The compose.yaml mounts a named volume for data persistence. Operators who ignore this guidance and expose File Browser directly will have no security updates to address future exploits in the JWT handling or command runner.

## Go 1.25.0 module dependencies include gorilla/mux for routing and golang-jwt for token handling

The go.mod file declares module github.com/filebrowser/filebrowser/v2 and requires Go 1.25.0. Key dependencies include github.com/gorilla/mux v1.8.1 for HTTP routing, github.com/gorilla/websocket v1.5.3 for WebSocket support, github.com/golang-jwt/jwt/v5 v5.3.1 for JWT implementation, and github.com/spf13/viper v1.21.0 for configuration management. The database layer uses go.etcd.io/bbolt v1.5.0. Caching uses github.com/jellydator/ttlcache/v3 v3.4.1 and github.com/redis/go-redis/v9 v9.21.0. File handling uses github.com/spf13/afero v1.15.0 for filesystem abstraction. The golang.org/x/crypto v0.54.0 provides cryptographic primitives. These versions are frozen as of the archive date; no updates will be applied for newly discovered vulnerabilities in these dependencies.

## Installation via Docker Compose is the only documented deployment method but offers no update path

The compose.yaml provides the only documented deployment configuration in the README. It starts filebrowser and redis containers with a shared network and persistent volume. There is no documented upgrade procedure for moving between versions since the project is archived. The Dockerfile builds a static binary into a minimal busybox image, but the compose.yaml pulls filebrowser/filebrowser:latest which will not receive new tags. Operators who deploy this composition cannot pull security updates because none will be published. The README directs users to the docs directory for installation, configuration, and build documentation, but those docs will also remain static. Anyone needing a maintained file manager should evaluate alternatives such as Nextcloud, ownCloud, or actively maintained forks.

## Conclusion

Use this only if you maintain a fork and can patch the JWT revocation and command execution flaws yourself. Do not use it for new deployments or expose it to the internet. Verify your reverse proxy terminates TLS and handles authentication before the traffic reaches File Browser.

## FAQ

### What is a FileBrowser?

File Browser provides a file managing interface within a specified directory for uploading, deleting, previewing, and editing files through a web interface.

### Is FileBrowser free?

File Browser is licensed under Apache License 2.0, making it free to use, modify, and distribute under the terms of that license.

### How do I install FileBrowser?

The compose.yaml shows a Docker Compose deployment with filebrowser/filebrowser:latest and redis:latest images, mapping port 8000 to container port 80.

### How do I remove FileBrowser?

The README does not document a removal procedure. Since it runs in containers, stopping and removing the containers and volumes would remove the deployment.

### How to use FileBrowser?

File Browser provides a web interface to manage files in a specified directory. The README directs users to the docs directory for usage documentation.

## Sources

- [Official README](https://github.com/filebrowser/filebrowser#readme)
- [Project repository](https://github.com/filebrowser/filebrowser)
- [Release notes](https://github.com/filebrowser/filebrowser/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/filebrowser-filebrowser
