CVE-2024-41255: Filestash

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.

Affected products

Published 2024-07-31. Last modified 2026-06-17.