Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x8qh-7475-c5mp | SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy |
Wed, 18 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sftpgo Project
Sftpgo Project sftpgo |
|
| CPEs | cpe:2.3:a:sftpgo_project:sftpgo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sftpgo Project
Sftpgo Project sftpgo |
|
| Metrics |
cvssV3_1
|
Mon, 16 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drakkan
Drakkan sftpgo |
|
| Vendors & Products |
Drakkan
Drakkan sftpgo |
Fri, 13 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Virtual Filesystem routing can lead to an authorization bypass. An authenticated attacker can craft specific file paths to bypass folder-level permissions or escape the boundaries of a configured Virtual Folder. This vulnerability is fixed in 2.7.1. | |
| Title | SFTPGo has a Path Traversal and Permission Bypass via Path Normalization Discrepancy | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-13T19:41:55.916Z
Reserved: 2026-03-07T16:40:05.884Z
Link: CVE-2026-30914
Updated: 2026-03-13T19:41:50.992Z
Status : Analyzed
Published: 2026-03-13T19:54:35.247
Modified: 2026-03-18T20:19:28.783
Link: CVE-2026-30914
No data.
OpenCVE Enrichment
Updated: 2026-03-23T13:40:22Z
Github GHSA