CVE-2020-15152: FTP-Srv Project FTP-Srv
Critical severity, CVSS 9.1. EPSS: 1.9% chance of exploitation in the next 30 days.
ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv before versions 2.19.6, 3.1.2, and 4.3.4 are vulnerable to Server-Side Request Forgery. The PORT command allows arbitrary IPs which can be used to cause the server to make a connection elsewhere. A possible workaround is blocking the PORT through the configuration. This issue is fixed in version2 2.19.6, 3.1.2, and 4.3.4. More information can be found on the linked advisory.
Affected products
- FTP-Srv Project FTP-Srv: before 2.19.6 (fixed in 2.19.6); from 3.0.0, before 3.1.2 (fixed in 3.1.2); from 4.0.0, before 4.3.4 (fixed in 4.3.4)
Published 2020-08-17. Last modified 2026-06-17.