VYPR

SFTPGo

by SFTPGo

CVEs (3)

  • CVE-2026-49244medJul 2, 2026
    risk 0.26cvss epss

    ## Summary The public web-client endpoint for partial ZIP downloads of a browsable share did not correctly confine the client-supplied files entries to the shared directory. A requester able to reach a public share could read files located outside the shared directory, as long…

  • CVE-2026-49245lowJul 2, 2026
    risk 0.07cvss epss

    ## Summary The inline query parameter on the browsable-share file download and on the authenticated user file download suppressed Content-Disposition: attachment, so an HTML file stored in a share or home directory could be served as text/html and execute in SFTPGo's web origin…

  • CVE-2026-10031Jul 30, 2026
    risk 0.00cvss epss 0.00

    SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions…