github.com/drakkan/sftpgo/v2
Full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob
Activity
- Latest release
- 1mo ago
- Total releases
- 38
- Cadence
- ~27 days
- Last 12 months
- 6
Reach
- Stars
- 12.4k
Details
- First release
- Nov 27, 2021
| Version | Released | |
|---|---|---|
v2.7.5
patch
|
v2.7.5
patch
Dependencies (70)
+ 62 more |
|
v2.7.4
patch
|
v2.7.4
patch
Dependencies (70)
+ 62 more |
|
v2.7.3
patch
|
v2.7.3
patch
Dependencies (70)
+ 62 more |
|
v2.7.2
patch
2 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev |
v2.7.2
patch
Dependencies (70)
+ 62 more |
|
v2.7.1
patch
2 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev |
v2.7.1
patch
Dependencies (70)
+ 62 more |
|
v2.7.0
minor
4 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v2.7.0
minor
Dependencies (68)
+ 60 more |
|
v2.6.6
patch
4 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v2.6.6
patch
Dependencies (72)
+ 64 more |
|
v2.6.5
patch
4 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev |
v2.6.5
patch
Dependencies (72)
+ 64 more |
|
v2.6.4
patch
5 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.6.4
patch
Dependencies (72)
+ 64 more |
|
v2.6.3
patch
6 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.6.3
patch
Dependencies (72)
+ 64 more |
|
v2.6.2
patch
7 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev |
v2.6.2
patch
Dependencies (72)
+ 64 more |
|
v2.6.1
patch
7 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev |
v2.6.1
patch
Dependencies (72)
+ 64 more |
|
v2.6.0
minor
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.6.0
minor
Dependencies (72)
+ 64 more |
|
v2.5.6
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.5.6
patch
Dependencies (73)
+ 65 more |
|
v2.4.6
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.6
patch
Dependencies (71)
+ 63 more |
|
v2.5.5
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.5.5
patch
Dependencies (73)
+ 65 more |
|
v2.5.4
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.5.4
patch
Dependencies (73)
+ 65 more |
|
v2.5.3
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.5.3
patch
Dependencies (73)
+ 65 more |
|
v2.5.2
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.5.2
patch
Dependencies (73)
+ 65 more |
|
v2.5.1
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.5.1
patch
Dependencies (73)
+ 65 more |
|
v2.5.0
minor
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.5.0
minor
Dependencies (73)
+ 65 more |
|
v2.4.5
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.5
patch
Dependencies (71)
+ 63 more |
|
v2.4.4
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.4
patch
Dependencies (71)
+ 63 more |
|
v2.4.3
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.3
patch
Dependencies (71)
+ 63 more |
|
v2.4.2
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.2
patch
Dependencies (71)
+ 63 more |
|
v2.4.1
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.1
patch
Dependencies (71)
+ 63 more |
|
v2.4.0
minor
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52309
GHSA-49cc-xrjf-9qf7
GO-2024-3283
Nov 21, 2024
SFTPGo allows administrators to restrict command execution from the EventManager
Medium
Network
Low
High
None
ImpactOne powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo, so they can access the database and server configurations. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. PatchesTo avoid this confusion, running system commands is now disabled by default, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI. https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4 WorkaroundsAllow EventManager to be used only by SFTPGo administrators who also have shell access. Fixed in
2.6.3
References
Updated Dec 02, 2024 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.4.0
minor
Dependencies (70)
+ 62 more |
|
v2.3.6
patch
7 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.6
patch
Dependencies (69)
+ 61 more |
|
v2.3.5
patch
7 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.5
patch
Dependencies (69)
+ 61 more |
|
v2.3.4
patch
8 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo Fixed in
2.3.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.4
patch
Dependencies (69)
+ 61 more |
|
v2.3.3
patch
9 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo Fixed in
2.3.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo Fixed in
2.3.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.3
patch
Dependencies (69)
+ 61 more |
|
v2.3.2
patch
9 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo Fixed in
2.3.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo Fixed in
2.3.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.2
patch
Dependencies (69)
+ 61 more |
|
v2.3.1
patch
9 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo Fixed in
2.3.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo Fixed in
2.3.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.1
patch
Dependencies (69)
+ 61 more |
|
v2.3.0
minor
9 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30915
GO-2026-4697
GHSA-m83q-5wr4-4gfp
Mar 16, 2026
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo Fixed in
2.7.1
Updated Mar 23, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52801
GO-2024-3300
GHSA-6943-qr24-82vx
Dec 02, 2024
sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo sftpgo vulnerable to brute force takeover of OpenID Connect session cookies in github.com/drakkan/sftpgo Fixed in
2.6.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo Fixed in
2.3.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo Fixed in
2.3.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.0
minor
Dependencies (69)
+ 61 more |
|
v2.2.3
patch
7 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo Fixed in
2.3.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo Fixed in
2.3.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.3
patch
Dependencies (55)
+ 47 more |
|
v2.2.2
patch
7 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo Fixed in
2.3.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo Fixed in
2.3.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.2
patch
Dependencies (55)
+ 47 more |
|
v2.2.1
patch
7 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo Fixed in
2.3.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo Fixed in
2.3.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.1
patch
Dependencies (56)
+ 48 more |
|
v2.2.0
initial
7 CVEs
CVE-2026-49244
GO-2026-5902
GHSA-h64p-8h4r-6gfh
Jul 07, 2026
SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo SFTPGo has path confinement bypass in public browsable share partial ZIP download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-49245
GO-2026-5900
GHSA-3vcg-pv95-pq54
Jul 07, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo SFTPGo has stored XSS via inline parameter on public shares and user file download in github.com/drakkan/sftpgo Fixed in
2.7.3
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30914
GO-2026-4699
GHSA-x8qh-7475-c5mp
Mar 16, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy in github.com/drakkan/sftpgo Fixed in
2.7.1
References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-24366
GO-2025-3458
GHSA-vj7w-3m8c-6vpx
Feb 07, 2025
SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo SFTPGo has insufficient sanitization of user provided rsync command in github.com/drakkan/sftpgo. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . Fixed in
2.6.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39220
GO-2022-1015
GHSA-cf7g-cm7q-rq7f
Aug 21, 2024
SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo Fixed in
2.3.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-36071
GO-2022-0964
GHSA-54qx-8p8w-xhg8
Aug 21, 2024
SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo Fixed in
2.3.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-37897
GO-2024-2940
GHSA-hw5f-6wvv-xcrh
Jun 28, 2024
SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo SFTPGo has insufficient access control for password reset in github.com/drakkan/sftpgo Fixed in
2.6.1
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.0
initial
Dependencies (56)
+ 48 more |