PT-2026-25355 · Sftpgo · Sftpgo

Published

2026-03-13

·

Updated

2026-03-25

·

CVE-2026-30915

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SFTPGo versions prior to 2.7.1
Description SFTPGo is an open source, event-driven file transfer solution. Versions of SFTPGo before 2.7.1 contain an input validation issue when handling dynamic group paths, such as home directories or key prefixes. When a group is configured with a dynamic home directory or key prefix using placeholders like %username%, the value replacing the placeholder is not adequately sanitized against relative path components. This allows a specially crafted username to cause the resulting path to resolve to a parent directory instead of the intended sub-directory. The vulnerable component is the handling of dynamic group paths. The vulnerable parameter is the username used in the placeholder.
Recommendations Update to version 2.7.1 or later.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30915
GHSA-M83Q-5WR4-4GFP
GO-2026-4697
SUSE-SU-2026:1042-1

Affected Products

Sftpgo