UNKNOWN Go

SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy

GHSA-x8qh-7475-c5mp · CVE-2026-30914 · GO-2026-4699

Published · Modified

Description

Impact

In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Virtual Filesystem routing can lead to an authorization bypass. An authenticated attacker can craft specific file paths to bypass folder-level permissions or escape the boundaries of a configured Virtual Folder.

Patches

This issue has been addressed in SFTPGo version 2.7.1. The fix introduces strict edge-level path normalization, ensuring that all protocol inputs are fully sanitized and resolved to canonical POSIX paths before any routing or permission evaluations occur.

Ready to move

Start Securing

Free, no credit card | First findings in minutes