CVE-2025-24366

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 7, 2025
CWE ID 78

Summary

CVE-2025-24366 affects SFTPGo, an open-source file transfer solution. The vulnerability arises from the application's SSH support, which allows for the execution of certain commands, including `rsync`. Although `rsync` is disabled by default and only works with the local filesystem, it can be activated by an authenticated remote user. The issue stems from insufficient sanitization of user-provided `rsync` commands, enabling the user to read or write files with the permissions of the SFTPGo server process. This vulnerability has been resolved in version v2.6.5, which includes checks on client-provided arguments. It is strongly recommended that users upgrade to the patched version, as no workarounds are currently available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share