The SFTPGo inline query parameter vulnerability (CVE-2026-49245) affects versions 2.2.0 to 2.7.3, allowing an attacker to serve attacker-controlled HTML files as text/html, potentially leading to execution of malicious content in a victim's browser context. This requires social engineering and suitable share or shared-folder access. The vulnerability is fixed in SFTPGo version 2.7.3. Administrators should [truncated]
The SFTPGo vulnerability (CVE-2026-49244) is a critical issue affecting the public web-client partial ZIP download endpoint for browsable shares. An unauthenticated requester can exploit this vulnerability by selecting a canonical path outside the shared directory, potentially leading to data disclosure. This issue was introduced in version 2.2.0 and fixed in version 2.7.3. Users of SFTPGo, especially tho [truncated]
CVE-2026-10031 is a permission bypass vulnerability in SFTPGo versions prior to 2.7.4. This vulnerability allows authenticated users with create_symlinks permission to create symbolic links in permitted directories, potentially leading to unauthorized access or modification of files in restricted directories. The vulnerability exists because operations are authorized against the link's directory permissio [truncated]