{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/filecodebox/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-64619"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FileCodeBox"],"_cs_severities":["high"],"_cs_tags":["rate-limit-bypass","vulnerability","web-application","file-sharing","data-exfiltration","cve"],"_cs_type":"advisory","_cs_vendors":["vastsa"],"content_html":"\u003cp\u003eCVE-2026-64619 describes a critical rate-limit bypass vulnerability affecting FileCodeBox versions prior to 2.4. This flaw resides within the \u003ccode\u003eIPRateLimit\u003c/code\u003e class, where the application fails to adequately verify the origin of \u003ccode\u003eX-Real-IP\u003c/code\u003e and \u003ccode\u003eX-Forwarded-For\u003c/code\u003e HTTP headers. Threat actors can exploit this by supplying unique, attacker-controlled IP values in these headers with each request, effectively circumventing the application's throttling mechanisms. This allows unauthenticated attackers to rapidly enumerate all possible share codes for files hosted on the platform. The primary goal of such an attack is to gain unauthorized access to and retrieve files belonging to other users, leading to data exfiltration. The vulnerability is attributed to a \u0026quot;Use of Less Trusted Source\u0026quot; (CWE-348) when processing these headers.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a FileCodeBox instance running a vulnerable version (prior to 2.4).\u003c/li\u003e\n\u003cli\u003eThe attacker crafts HTTP requests targeting FileCodeBox endpoints that handle shared content or are subject to rate limiting for access attempts.\u003c/li\u003e\n\u003cli\u003eThe attacker injects \u003ccode\u003eX-Real-IP\u003c/code\u003e and \u003ccode\u003eX-Forwarded-For\u003c/code\u003e HTTP headers into these requests, assigning unique, attacker-controlled IP addresses for each individual request.\u003c/li\u003e\n\u003cli\u003eThe vulnerable \u003ccode\u003eIPRateLimit\u003c/code\u003e class in FileCodeBox processes these requests without adequately verifying the trustworthiness of the \u003ccode\u003eX-Real-IP\u003c/code\u003e and \u003ccode\u003eX-Forwarded-For\u003c/code\u003e headers.\u003c/li\u003e\n\u003cli\u003eThis critical flaw bypasses the application's rate limiting mechanism, enabling the attacker to send a high volume of requests in rapid succession.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages these rapid requests to systematically enumerate or brute-force all possible share codes for files hosted on the platform.\u003c/li\u003e\n\u003cli\u003eUpon successfully identifying valid share codes, the attacker makes subsequent requests using these codes to retrieve the corresponding files.\u003c/li\u003e\n\u003cli\u003eThe attacker successfully gains unauthorized access to and exfiltrates sensitive or private files belonging to other FileCodeBox users without requiring any form of authentication.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-64619 allows unauthenticated attackers to bypass security controls designed to prevent brute-force attacks and unauthorized access. The primary impact is the unauthorized retrieval of other users' files, potentially leading to widespread data exfiltration. While no specific victim counts or targeted sectors are provided in the advisory, any organization or individual using FileCodeBox versions prior to 2.4 could be at risk of having their shared files accessed by malicious actors without their consent. This can result in significant privacy breaches, exposure of sensitive information, and reputational damage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update FileCodeBox instances to version 2.4 or later to patch CVE-2026-64619. Refer to the GitHub release at \u003ccode\u003ehttps://github.com/vastsa/FileCodeBox/releases/tag/V2.4\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eReview the commit \u003ccode\u003ehttps://github.com/vastsa/FileCodeBox/commit/1b6d8e7277d3cfa34dc7a85803731d927b2147da\u003c/code\u003e for details on the fix and implement similar robust verification of \u003ccode\u003eX-Real-IP\u003c/code\u003e and \u003ccode\u003eX-Forwarded-For\u003c/code\u003e headers if running a custom or forked version.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for a high volume of requests with rapidly changing \u003ccode\u003eX-Real-IP\u003c/code\u003e or \u003ccode\u003eX-Forwarded-For\u003c/code\u003e headers, particularly those targeting file sharing or download endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T19:28:03Z","date_published":"2026-07-20T19:28:03Z","id":"https://feed.craftedsignal.io/briefs/2026-07-filecodebox-rate-limit-bypass/","summary":"Unauthenticated attackers can bypass rate limits in FileCodeBox versions before 2.4 due to a vulnerability in the IPRateLimit class, allowing them to enumerate share codes and retrieve other users' files without authentication by spoofing X-Real-IP and X-Forwarded-For headers without proper verification.","title":"CVE-2026-64619: FileCodeBox Rate Limit Bypass Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-filecodebox-rate-limit-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - FileCodeBox","version":"https://jsonfeed.org/version/1.1"}