{"schema_version":"1.7.5","id":"GHSA-x8qh-7475-c5mp","published":"2026-03-13T18:55:52Z","modified":"2026-03-24T21:01:24.646638Z","aliases":["CVE-2026-30914","GO-2026-4699"],"summary":"SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy","details":"### Impact\n\nIn SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Virtual Filesystem routing can lead to an authorization bypass. An authenticated attacker can craft specific file paths to bypass folder-level permissions or escape the boundaries of a configured Virtual Folder.\n\n\n### Patches\n\nThis issue has been addressed in SFTPGo version 2.7.1. The fix introduces strict edge-level path normalization, ensuring that all protocol inputs are fully sanitized and resolved to canonical POSIX paths before any routing or permission evaluations occur.","affected":[{"package":{"name":"github.com/drakkan/sftpgo/v2","ecosystem":"Go","purl":"pkg:golang/github.com/drakkan/sftpgo/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.7.1"}]}],"database_specific":{"last_known_affected_version_range":"<= 2.7.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-x8qh-7475-c5mp/GHSA-x8qh-7475-c5mp.json"}},{"package":{"name":"github.com/drakkan/sftpgo","ecosystem":"Go","purl":"pkg:golang/github.com/drakkan/sftpgo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.2.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-x8qh-7475-c5mp/GHSA-x8qh-7475-c5mp.json"}}],"references":[{"type":"WEB","url":"https://github.com/drakkan/sftpgo/security/advisories/GHSA-x8qh-7475-c5mp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30914"},{"type":"WEB","url":"https://github.com/drakkan/sftpgo/commit/2f092d128917e2c059520a2ce3e22c3b5ea7ffd6"},{"type":"PACKAGE","url":"https://github.com/drakkan/sftpgo"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2026-4699"}],"database_specific":{"cwe_ids":["CWE-22"],"github_reviewed":true,"github_reviewed_at":"2026-03-13T18:55:52Z","nvd_published_at":"2026-03-13T19:54:35Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}