Patch Commitpatch
https://github.com/vastsa/FileCodeBox/commit/1b6d8e7277d3cfa34dc7a85803731d927b2147da CVE-2026-64619
HIGH
FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
Record summary
CVE-2026-64619 has a selected CVSS score of 8.7 (high).
Description
FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers without verification of trusted reverse proxy origin. Attackers can supply unique spoofed IP values on each request to enumerate all possible share codes and retrieve other users' files without authentication.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 20, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FileCodeBoxBrowse vastsa / FileCodeBoxDefault status: unaffected | CVE List | Before 2.4 | affected |
References
5Researcher DisclosureTechnical descriptionissue tracking
https://github.com/vastsa/FileCodeBox/issues/479 FileCodeBox 2.4 Release Notespatchrelease notes
https://github.com/vastsa/FileCodeBox/releases/tag/V2.4 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-64619 vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/filecodebox-anti-bruteforce-rate-limit-bypass-via-spoofed-headers