PatchSiren

drakkan CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW drakkan CVE published 2026-08-20

CVE-2026-49245

The SFTPGo inline query parameter vulnerability (CVE-2026-49245) affects versions 2.2.0 to 2.7.3, allowing an attacker to serve attacker-controlled HTML files as text/html, potentially leading to execution of malicious content in a victim's browser context. This requires social engineering and suitable share or shared-folder access. The vulnerability is fixed in SFTPGo version 2.7.3. Administrators should [truncated]

MEDIUM drakkan CVE published 2026-08-20

CVE-2026-49244

The SFTPGo vulnerability (CVE-2026-49244) is a critical issue affecting the public web-client partial ZIP download endpoint for browsable shares. An unauthenticated requester can exploit this vulnerability by selecting a canonical path outside the shared directory, potentially leading to data disclosure. This issue was introduced in version 2.2.0 and fixed in version 2.7.3. Users of SFTPGo, especially tho [truncated]

LOW drakkan CVE published 2026-07-30

CVE-2026-10031

CVE-2026-10031 is a permission bypass vulnerability in SFTPGo versions prior to 2.7.4. This vulnerability allows authenticated users with create_symlinks permission to create symbolic links in permitted directories, potentially leading to unauthorized access or modification of files in restricted directories. The vulnerability exists because operations are authorized against the link's directory permissio [truncated]