Caught blind, first pass
Eight matched outright and five flagged as the same underlying flaw.
Sample report
Explore the complete Dokima report from a pinned release of File Browser, an open-source web file manager. Every finding is published with its technical evidence, validation notes and suggested remediation.
File Browser stopped accepting private security reports when its repository became read-only on 1 September 2026. The temporary responsible-disclosure redactions have therefore been removed. This is the untouched report snapshot, including every finding and the benchmark scorecard showing what Dokima did not find.
Run disclosure
a1e442ef9e4a4232bbcA fair test
Dokima reviewed the pinned source with no advisory, no hint and no expected answer to aim at. What you are reading is the report it produced on its own, findings and review notes included.
We then took every security advisory later published for this exact release and checked Dokima's report against each one by root cause, crediting nothing that was only a loose overlap. We hold a hard line: anything Dokima had not found by the snapshot linked here is scored against it in full, and every one is on the scorecard below.
The blind test result
We pinned File Browser to v2.63.5, a release from before its security advisories were published, and ran Dokima against it with no knowledge of them. Its first blind pass caught 13 of the 17 issues later disclosed for this exact build. Its continuous re-review of the same source then caught the critical self-signup issue it had not found at first, bringing the total to 14 - including all three criticals - plus 43 further findings in the original report snapshot. The full technical detail for all findings is available in the report linked above.
CVE-2026-54096CVE-2026-54093CVE-2026-62684Eight matched outright and five flagged as the same underlying flaw.
The critical self-signup scope issue, caught as Dokima kept reviewing the same build.
All are published with their technical detail, evidence and remediation.
One High, one Medium, one Low - left on the scorecard in full.
GHSA-6759-996p-gpj6Self-signup accounts inherit the server root as their scope.
CVE-2026-54088The auth hook drops login input into a shell command, allowing pre-auth remote code execution.
CVE-2026-54089A forged proxy-auth header impersonates any user, including admins.
CVE-2026-54092The public login API accepts unbounded input, exhausting CPU and memory.
CVE-2026-55667A create-only user deletes files outside their scope through a followed symlink.
CVE-2026-62685Username normalisation lets two distinct accounts share one home directory.
GHSA-576v-w77m-gr84Case-folded signup usernames collide onto one home directory.
CVE-2026-54091Public directory-share rules are checked in the wrong path namespace, exposing blocked files.
CVE-2026-54097An over-broad path prefix lets one user delete other users' share links.
CVE-2026-54096A public share made for a not-yet-existing path exposes whatever is later placed there.
CVE-2026-54094A scoped user reads and writes outside their scope through an in-scope symlink.
GHSA-ffv3-7h97-993qtus uploads ignore the declared length, letting a user exhaust disk.
CVE-2026-55668A scoped user writes outside their scope through a dangling symlink.
CVE-2026-54093Backslash separators in archived filenames allow path traversal on download.
GHSA-7whw-q6gh-xr59The checksum endpoint skips the download permission check, leaking file hashes.
CVE-2026-62683A trailing-slash delete leaves a stale public share record behind.
CVE-2026-62684The share API returns a share's password hash and bypass token.
How we scored it. Found means a Dokima finding identified the same underlying flaw in the same code. In a few cases it drew a narrower conclusion than the advisory. Not found means the runs behind this snapshot did not surface it - scored against Dokima in full, with no middle ground. Dokima is built to keep running against the same code, and a later pass may pick up what an earlier one did not. The "also found" column counts 43 findings outside this original 17-advisory benchmark set, at Dokima's own severity rating. All are published in full in the report, including the findings that were temporarily redacted during the maintainer's reporting window.
Dokima re-reviews continuously as code changes, so a first pass is where it starts, not where it stops.
What you can inspect
Try it on your own source
Start a full-product 21-day trial for your engineering team. No payment card required.