๐Ÿ” CVE Alert

CVE-2026-49245

LOW 3.7

SFTPGo: Stored XSS via inline parameter on public shares and user file download

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored in a share or home directory to be served as text/html in the SFTPGo web origin. An attacker who can place the file can send a crafted link to a victim, and opening that link executes the stored content in the victim's browser context. Exploitation requires social engineering and suitable share or shared-folder access, while HttpOnly session cookies limit direct cookie theft. This issue is fixed in version 2.7.3.

CWE CWE-79
Vendor drakkan
Product sftpgo
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for drakkan sftpgo

Be the first to know when new low vulnerabilities affecting drakkan sftpgo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

drakkan / sftpgo
>= 2.2.0 < 2.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/drakkan/sftpgo/security/advisories/GHSA-3vcg-pv95-pq54 github.com: https://github.com/drakkan/sftpgo/commit/b5409a478138fca5f1d369ae5d47f753156cbd15 github.com: https://github.com/drakkan/sftpgo/releases/tag/v2.7.3