File Transfer Solution Vulnerability in SFTPGo Product
CVE-2026-49245

3.7LOW

Key Information:

Vendor

Drakkan

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-49245?

SFTPGo, an open-source file transfer solution, is susceptible to a vulnerability where the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses the Content-Disposition header. This flaw allows an attacker to store an HTML file in a share or home directory, which can then be served as text/html under specific conditions. If a victim opens a crafted link sent by the attacker, the malicious content executes within the victim's browser context. Exploiting this vulnerability requires social engineering tactics and appropriate access to shared folders. HttpOnly session cookies provide some protection against direct cookie theft, but caution is advised. This issue has been addressed in version 2.7.3.

Affected Version(s)

sftpgo >= 2.2.0 < 2.7.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.