SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Virtual Filesystem routing can lead to an authorization bypass. An authenticated attacker can craft specific file paths to bypass folder-level permissions or escape the boundaries of a configured Virtual Folder. This vulnerability is fixed in 2.7.1.
References
| Link | Resource |
|---|---|
| https://github.com/drakkan/sftpgo/security/advisories/GHSA-x8qh-7475-c5mp | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-13 19:54
Updated : 2026-03-18 20:19
NVD link : CVE-2026-30914
Mitre link : CVE-2026-30914
CVE.ORG link : CVE-2026-30914
JSON object : View
Products Affected
sftpgo_project
- sftpgo
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
