PT-2026-55447 · Sftpgo · Sftpgo

CVE-2026-49245

·

Published

2026-07-02

·

Updated

2026-08-21

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SFTPGo versions prior to 2.7.3
Description A stored Cross-Site Scripting (XSS) issue exists where the inline query parameter on the browsable-share file download and authenticated user file download endpoints suppresses the Content-Disposition: attachment header. This allows an HTML file stored in a share or home directory to be served as text/html and executed within the SFTPGo web origin. Exploitation requires an attacker to upload a crafted file and a victim to open the link via social engineering. Because session cookies are HttpOnly, they cannot be read by the injected script.
Recommendations Upgrade to version 2.7.3.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49245
GHSA-3VCG-PV95-PQ54
GO-2026-5900
OPENSUSE-SU-2026:21483-1

Affected Products

Sftpgo