File Transfer Solution Vulnerability in SFTPGo Product
CVE-2026-49245
What is CVE-2026-49245?
SFTPGo, an open-source file transfer solution, is susceptible to a vulnerability where the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses the Content-Disposition header. This flaw allows an attacker to store an HTML file in a share or home directory, which can then be served as text/html under specific conditions. If a victim opens a crafted link sent by the attacker, the malicious content executes within the victim's browser context. Exploiting this vulnerability requires social engineering tactics and appropriate access to shared folders. HttpOnly session cookies provide some protection against direct cookie theft, but caution is advised. This issue has been addressed in version 2.7.3.
Affected Version(s)
sftpgo >= 2.2.0 < 2.7.2
