logo

Critical Path Traversal Flaw in basic-ftp Exposes Node.js Apps to Arbitrary File Writes

ID: caf6e968-9c3e-5af2-8afd-40f7956f4c7c

STIX ID: report--caf6e968-9c3e-5af2-8afd-40f7956f4c7c

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-02

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical path traversal vulnerability (CVE-2026-27699, CVSS 9.1) in the basic-ftp Node.js library's downloadToDir() allows a malicious FTP server to supply filenames with traversal sequences (e.g., ../../../etc/passwd) that are combined with the local path and written outside the intended directory, enabling arbitrary file writes and possible RCE; maintainers patched the issue in v5.2.0 and users should upgrade or avoid downloadToDir() when connecting to untrusted servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.