Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m83q-5wr4-4gfp | SFTPGo improperly sanitizes placeholders in group home directories/key prefixes |
Wed, 18 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sftpgo Project
Sftpgo Project sftpgo |
|
| CPEs | cpe:2.3:a:sftpgo_project:sftpgo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sftpgo Project
Sftpgo Project sftpgo |
|
| Metrics |
cvssV3_1
|
Mon, 16 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drakkan
Drakkan sftpgo |
|
| Vendors & Products |
Drakkan
Drakkan sftpgo |
Fri, 13 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SFTPGo is an open source, event-driven file transfer solution. SFTPGo versions before v2.7.1 contain an input validation issue in the handling of dynamic group paths, for example, home directories or key prefixes. When a group is configured with a dynamic home directory or key prefix using placeholders like %username%, the value replacing the placeholder is not strictly sanitized against relative path components. Consequently, if a user is created with a specially crafted username the resulting path may resolve to a parent directory instead of the intended sub-directory. This issue is fixed in version v2.7.1 | |
| Title | SFTPGo improperly sanitizes placeholders in group home directories/key prefixes | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-13T19:41:17.258Z
Reserved: 2026-03-07T16:40:05.884Z
Link: CVE-2026-30915
Updated: 2026-03-13T19:41:13.342Z
Status : Analyzed
Published: 2026-03-13T19:54:35.410
Modified: 2026-03-18T20:16:46.693
Link: CVE-2026-30915
No data.
OpenCVE Enrichment
Updated: 2026-03-23T13:40:21Z
Github GHSA