CVE-2026-49245: Drakkan Sftpgo
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored in a share or home directory to be served as text/html in the SFTPGo web origin. An attacker who can place the file can send a crafted link to a victim, and opening that link executes the stored content in the victim's browser context. Exploitation requires social engineering and suitable share or shared-folder access, while HttpOnly session cookies limit direct cookie theft. This issue is fixed in version 2.7.3.
Affected products
- Drakkan Sftpgo: from 2.2.0, before 2.7.2 (fixed in 2.7.2)
Published 2026-08-20. Last modified 2026-09-18.