Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3vcg-pv95-pq54 | SFTPGo has stored XSS via inline parameter on public shares and user file download |
Fri, 21 Aug 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drakkan
Drakkan sftpgo |
|
| Vendors & Products |
Drakkan
Drakkan sftpgo |
Thu, 20 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored in a share or home directory to be served as text/html in the SFTPGo web origin. An attacker who can place the file can send a crafted link to a victim, and opening that link executes the stored content in the victim's browser context. Exploitation requires social engineering and suitable share or shared-folder access, while HttpOnly session cookies limit direct cookie theft. This issue is fixed in version 2.7.3. | |
| Title | SFTPGo: Stored XSS via inline parameter on public shares and user file download | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T21:52:20.219Z
Reserved: 2026-05-28T14:33:01.178Z
Link: CVE-2026-49245
No data.
Status : Received
Published: 2026-08-20T22:17:20.107
Modified: 2026-08-20T22:17:20.107
Link: CVE-2026-49245
No data.
OpenCVE Enrichment
Updated: 2026-08-21T00:30:07Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Github GHSA