Critical Path Traversal Flaw in basic-ftp Exposes Node.js Apps to Arbitrary File Writes
ID: caf6e968-9c3e-5af2-8afd-40f7956f4c7c
STIX ID: report--caf6e968-9c3e-5af2-8afd-40f7956f4c7c
Feed Name: securityonline.info
Threat Score
A critical path traversal vulnerability (CVE-2026-27699, CVSS 9.1) in the basic-ftp Node.js library's downloadToDir() allows a malicious FTP server to supply filenames with traversal sequences (e.g., ../../../etc/passwd) that are combined with the local path and written outside the intended directory, enabling arbitrary file writes and possible RCE; maintainers patched the issue in v5.2.0 and users should upgrade or avoid downloadToDir() when connecting to untrusted servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
