VYPR

SFTPGo

by SFTPGo

CVEs (1)

  • CVE-2026-49245LowAug 20, 2026
    risk 0.24cvss 3.7epss 0.00

    SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored…