Sample report

See the work, not just the promise.

Explore the complete Dokima report from a pinned release of File Browser, an open-source web file manager. Every finding is published with its technical evidence, validation notes and suggested remediation.

About this reportThe complete original report, published unredacted.

File Browser stopped accepting private security reports when its repository became read-only on 1 September 2026. The temporary responsible-disclosure redactions have therefore been removed. This is the untouched report snapshot, including every finding and the benchmark scorecard showing what Dokima did not find.

Run disclosure

A real codebase, pinned so the result can be checked.

  • Target: File Browser v2.63.5
  • Source commit: a1e442ef9e4a
  • Generated: 29 July 2026 at 07:54 UTC
  • Dokima build: 4232bbc
  • Runner and model: Claude with Opus

A fair test

Dokima went in blind.

Dokima reviewed the pinned source with no advisory, no hint and no expected answer to aim at. What you are reading is the report it produced on its own, findings and review notes included.

We then took every security advisory later published for this exact release and checked Dokima's report against each one by root cause, crediting nothing that was only a loose overlap. We hold a hard line: anything Dokima had not found by the snapshot linked here is scored against it in full, and every one is on the scorecard below.

The blind test result

Dokima caught every critical, and 14 of the 17 vulnerabilities disclosed in this build.

We pinned File Browser to v2.63.5, a release from before its security advisories were published, and ran Dokima against it with no knowledge of them. Its first blind pass caught 13 of the 17 issues later disclosed for this exact build. Its continuous re-review of the same source then caught the critical self-signup issue it had not found at first, bringing the total to 14 - including all three criticals - plus 43 further findings in the original report snapshot. The full technical detail for all findings is available in the report linked above.

SeverityCaughtAlso foundNot found
Critical3 of 3--
High6 of 7+3CVE-2026-54096
Medium4 of 5+14CVE-2026-54093
Low1 of 2+26CVE-2026-62684
Total14 of 17+433
13

Caught blind, first pass

Eight matched outright and five flagged as the same underlying flaw.

1

Caught on re-review

The critical self-signup scope issue, caught as Dokima kept reviewing the same build.

43

Further findings in the snapshot

All are published with their technical detail, evidence and remediation.

3

Not yet found, shown below

One High, one Medium, one Low - left on the scorecard in full.

Disclosed vulnerabilityMatching Dokima findingResult
CriticalGHSA-6759-996p-gpj6

Self-signup accounts inherit the server root as their scope.

Not found on the first pass, caught on continuous re-review of the same build
Found
CriticalCVE-2026-54088

The auth hook drops login input into a shell command, allowing pre-auth remote code execution.

Auth hook forks a subprocess on every login
Found
CriticalCVE-2026-54089

A forged proxy-auth header impersonates any user, including admins.

Proxy auth trusts an unvalidated header
Found
HighCVE-2026-54092

The public login API accepts unbounded input, exhausting CPU and memory.

Login and signup read an unbounded request body
Found
HighCVE-2026-55667

A create-only user deletes files outside their scope through a followed symlink.

Symlinks escape the user root on reads and writes
Found
HighCVE-2026-62685

Username normalisation lets two distinct accounts share one home directory.

Lossy username handling shares a home directory
Found
HighGHSA-576v-w77m-gr84

Case-folded signup usernames collide onto one home directory.

Lossy username handling shares a home directory
Found
HighCVE-2026-54091

Public directory-share rules are checked in the wrong path namespace, exposing blocked files.

Share rules checked in the wrong path namespace
Found
HighCVE-2026-54097

An over-broad path prefix lets one user delete other users' share links.

Share-link delete matches paths too loosely
Found
HighCVE-2026-54096

A public share made for a not-yet-existing path exposes whatever is later placed there.

Not flagged
Not found
MediumCVE-2026-54094

A scoped user reads and writes outside their scope through an in-scope symlink.

Symlinks escape the user root on reads and writes
Found
MediumGHSA-ffv3-7h97-993q

tus uploads ignore the declared length, letting a user exhaust disk.

tus PATCH upload has no read deadline or concurrency cap
Found
MediumCVE-2026-55668

A scoped user writes outside their scope through a dangling symlink.

Symlinks escape the user root on writes
Found
MediumCVE-2026-54093

Backslash separators in archived filenames allow path traversal on download.

Not flagged
Not found
MediumGHSA-7whw-q6gh-xr59

The checksum endpoint skips the download permission check, leaking file hashes.

Checksum endpoint skips the download permission check
Found
LowCVE-2026-62683

A trailing-slash delete leaves a stale public share record behind.

Share-link delete matches paths too loosely
Found
LowCVE-2026-62684

The share API returns a share's password hash and bypass token.

Not flagged
Not found

How we scored it. Found means a Dokima finding identified the same underlying flaw in the same code. In a few cases it drew a narrower conclusion than the advisory. Not found means the runs behind this snapshot did not surface it - scored against Dokima in full, with no middle ground. Dokima is built to keep running against the same code, and a later pass may pick up what an earlier one did not. The "also found" column counts 43 findings outside this original 17-advisory benchmark set, at Dokima's own severity rating. All are published in full in the report, including the findings that were temporarily redacted during the maintainer's reporting window.

Dokima re-reviews continuously as code changes, so a first pass is where it starts, not where it stops.

What you can inspect

The same report structure your team receives.

  • Plain-English issue descriptions
  • Technical evidence and affected scope
  • Severity, confidence and verification status
  • Attack path and practical outcome
  • Detailed and plain-English remediation
  • Finding status and review annotations
  • Complete technical detail for every finding in the snapshot

Try it on your own source

Evaluate Dokima against a codebase your team already understands.

Start a full-product 21-day trial for your engineering team. No payment card required.