Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49244— SFTPGo: Path confinement bypass in public browsable share partial ZIP download

Quick assessment

Affected
drakkan sftpgo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SFTPGo 是一个开源的、事件驱动的文件传输解决方案。在版本 2.2.0 至 2.7.3 之间,其公开 Web 客户端的“部分 ZIP 下载”端点(用于可浏览共享目录)在验证客户端提供的文件条目时,仅采用原始字节前缀匹配的方式,而非基于目录边界感知的检查方式。未认证的请求者若能访问该公开共享目录,当目标路径以共享目录名称开头时(例如,与共享目录具有相同前缀的同级路径),便可以选择共享目录之外的规范化路径。随后,该端点会将超出范围的包含在生成的下载文件中,从而导致其内容被泄露。该问题已在版本 2.7.3 中修复。

CVSS 5.9 · Medium EPSS 0.37% · P30

Possible ATT&CK Techniques 1 AI

T1005 · Data from Local System

Affected Version Matrix 1

VendorProduct Version RangeStatus
drakkan sftpgo >= 2.2.0 < 2.7.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-49244

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SFTPGo: Path confinement bypass in public browsable share partial ZIP download
Source: CVE Program / CVE List V5
Vulnerability Description
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison rather than a directory-boundary-aware check. An unauthenticated requester who can reach a public share can select a canonical path outside the shared directory when the target path begins with the shared directory's name, such as a sibling path that shares the same prefix. The endpoint then includes the out-of-scope file in the generated download, disclosing its contents. This issue is fixed in version 2.7.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
drakkan sftpgo >= 2.2.0 < 2.7.2 -

II. Public POCs for CVE-2026-49244

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49244

登录查看更多情报信息。

Patches & Fixes for CVE-2026-49244 (1)

Vendor Advisories for CVE-2026-49244 (1)

Vendor Pages for CVE-2026-49244 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-49244

No comments yet


Leave a comment