5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether basic-ftp is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-44240
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
HIGH 7.5
CVE-2026-41324
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
HIGH 8.6
CVE-2026-39983
basic-ftp has FTP Command Injection via CRLF
HIGH 8.2
GHSA-6v7q-wjvx-w8wg
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
CRITICAL 9.1
CVE-2026-27699
Basic FTP has Path Traversal Vulnerability in its downloadToDir() method
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes