SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored in a share or home directory to be served as text/html in the SFTPGo web origin. An attacker who can place the file can send a crafted link to a victim, and opening that link executes the stored content in the victim's browser context. Exploitation requires social engineering and suitable share or shared-folder access, while HttpOnly session cookies limit direct cookie theft. This issue is fixed in version 2.7.3.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3vcg-pv95-pq54 | SFTPGo has stored XSS via inline parameter on public shares and user file download |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 21 Aug 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drakkan
Drakkan sftpgo |
|
| Vendors & Products |
Drakkan
Drakkan sftpgo |
Thu, 20 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file stored in a share or home directory to be served as text/html in the SFTPGo web origin. An attacker who can place the file can send a crafted link to a victim, and opening that link executes the stored content in the victim's browser context. Exploitation requires social engineering and suitable share or shared-folder access, while HttpOnly session cookies limit direct cookie theft. This issue is fixed in version 2.7.3. | |
| Title | SFTPGo: Stored XSS via inline parameter on public shares and user file download | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T21:52:20.219Z
Reserved: 2026-05-28T14:33:01.178Z
Link: CVE-2026-49245
No data.
Status : Received
Published: 2026-08-20T22:17:20.107
Modified: 2026-08-20T22:17:20.107
Link: CVE-2026-49245
No data.
OpenCVE Enrichment
Updated: 2026-08-21T01:15:07Z
Weaknesses
Github GHSA