๐Ÿ” CVE Alert

CVE-2026-49244

MEDIUM 5.9

SFTPGo: Path confinement bypass in public browsable share partial ZIP download

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison rather than a directory-boundary-aware check. An unauthenticated requester who can reach a public share can select a canonical path outside the shared directory when the target path begins with the shared directory's name, such as a sibling path that shares the same prefix. The endpoint then includes the out-of-scope file in the generated download, disclosing its contents. This issue is fixed in version 2.7.3.

CWE CWE-22
Vendor drakkan
Product sftpgo
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for drakkan sftpgo

Be the first to know when new medium vulnerabilities affecting drakkan sftpgo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

drakkan / sftpgo
>= 2.2.0 < 2.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/drakkan/sftpgo/security/advisories/GHSA-h64p-8h4r-6gfh github.com: https://github.com/drakkan/sftpgo/commit/52a56584c417e325aea35ab23849422a90ba512f github.com: https://github.com/drakkan/sftpgo/releases/tag/v2.7.3