blob: df545fbcb2ba43017fc155df65b3ed66849561b9 [file] [edit]
id: GO-2026-4697
modules:
- module: github.com/drakkan/sftpgo
vulnerable_at: 1.2.2
- module: github.com/drakkan/sftpgo/v2
versions:
- introduced: 2.3.0
- fixed: 2.7.1
vulnerable_at: 2.7.0
summary: SFTPGo improperly sanitizes placeholders in group home directories/key prefixes in github.com/drakkan/sftpgo
cves:
- CVE-2026-30915
ghsas:
- GHSA-m83q-5wr4-4gfp
references:
- advisory: https://github.com/drakkan/sftpgo/security/advisories/GHSA-m83q-5wr4-4gfp
source:
id: GHSA-m83q-5wr4-4gfp
created: 2026-03-13T19:27:28.345828609Z
review_status: UNREVIEWED