UNKNOWN Go
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy
GHSA-x8qh-7475-c5mp · CVE-2026-30914 · GO-2026-4699
Published · Modified
Description
Impact
In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Virtual Filesystem routing can lead to an authorization bypass. An authenticated attacker can craft specific file paths to bypass folder-level permissions or escape the boundaries of a configured Virtual Folder.
Patches
This issue has been addressed in SFTPGo version 2.7.1. The fix introduces strict edge-level path normalization, ensuring that all protocol inputs are fully sanitized and resolved to canonical POSIX paths before any routing or permission evaluations occur.
References
- WEB https://github.com/drakkan/sftpgo/security/advisories/GHSA-x8qh-7475-c5mp
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-30914
- WEB https://github.com/drakkan/sftpgo/commit/2f092d128917e2c059520a2ce3e22c3b5ea7ffd6
- PACKAGE https://github.com/drakkan/sftpgo
- WEB https://pkg.go.dev/vuln/GO-2026-4699
Ready to move
Start Securing
Free, no credit card | First findings in minutes