Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-27699

Опубликовано: 25 фев. 2026
Источник: debian
EPSS Низкий

Описание

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-proxy-agentsfixed0~2025070717+~cs15.2.7-1package
node-proxy-agentsfixed0~2024040606-6+deb13u1trixiepackage

Примечания

  • https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-5rq4-664w-9x2c

  • https://github.com/patrickjuchli/basic-ftp/commit/2a2a0e6514357b9eda07c2f8afbd3f04727a7cd9 (v5.2.0)

EPSS

Процентиль: 25%
0.00087
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 месяца назад

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.

CVSS3: 7.5
redhat
около 1 месяца назад

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.

CVSS3: 9.1
nvd
около 1 месяца назад

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.

CVSS3: 9.1
github
около 1 месяца назад

Basic FTP has Path Traversal Vulnerability in its downloadToDir() method

EPSS

Процентиль: 25%
0.00087
Низкий