Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49245— SFTPGo: Stored XSS via inline parameter on public shares and user file download

Quick assessment

Affected
drakkan sftpgo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SFTPGo 是一个开源、事件驱动的文件传输解决方案。在版本 2.2.0 至 2.7.3 之间,浏览共享文件下载和经过身份验证的用户文件下载中的内联查询参数会抑制 Content-Disposition: attachment 响应头。这使得攻击者可以将存储在共享目录或用户主目录中的 HTML 文件作为 text/html 类型,在 SFTPGo 的 Web 上下文中被提供。 攻击者若能将文件放置到相关目录中,即可向受害者发送一个精心构造的链接;受害者打开该链接后,存储的内容将在受害者浏览器的上下文中执行。该漏洞的

CVSS 3.7 · Low EPSS 0.20% · P10

Affected Version Matrix 1

VendorProduct Version RangeStatus
drakkan sftpgo >= 2.2.0 < 2.7.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-49245

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SFTPGo: Stored XSS via inline parameter on public shares and user file download
Source: CVE Program / CVE List V5
Vulnerability Description
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored in a share or home directory to be served as text/html in the SFTPGo web origin. An attacker who can place the file can send a crafted link to a victim, and opening that link executes the stored content in the victim's browser context. Exploitation requires social engineering and suitable share or shared-folder access, while HttpOnly session cookies limit direct cookie theft. This issue is fixed in version 2.7.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
drakkan sftpgo >= 2.2.0 < 2.7.2 -

II. Public POCs for CVE-2026-49245

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49245

登录查看更多情报信息。

Patches & Fixes for CVE-2026-49245 (1)

Vendor Advisories for CVE-2026-49245 (1)

Vendor Pages for CVE-2026-49245 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-49245

No comments yet


Leave a comment