CVE-2025-24366
Last modified
CVE-2025-24366 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. SFTPGo is an open source, event-driven file transfer solution. SFTPGo supports execution of a defined set of commands via SSH. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
SFTPGo is an open source, event-driven file transfer solution. SFTPGo supports execution of a defined set of commands via SSH. Besides a set of default commands some optional commands can be activated, one of them being `rsync`. It is disabled in the default configuration and it is limited to the local filesystem, it does not work with cloud/remote storage backends. Due to missing sanitization of the client provided `rsync` command, an authenticated remote user can use some options of the rsync command to read or write files with the permissions of the SFTPGo server process. This issue was fixed in version v2.6.5 by checking the client provided arguments. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-24366?
How severe is CVE-2025-24366?
How do I fix CVE-2025-24366?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-24360Nuxt is an open-source web development framework for Vue.js.…5.3
- CVE-2025-24361Nuxt is an open-source web development framework for Vue.js.…5.3
- CVE-2025-24362In some circumstances, debug artifacts uploaded by the CodeQ…7.1
- CVE-2025-24363The HL7 FHIR IG publisher is a tool to take a set of inputs …4.2
- CVE-2025-24364vaultwarden is an unofficial Bitwarden compatible server wri…7.2
- CVE-2025-24365vaultwarden is an unofficial Bitwarden compatible server wri…7.5
- CVE-2025-24367Cacti is an open source performance and fault management fra…8.8
- CVE-2025-24368Cacti is an open source performance and fault management fra…7.5
- CVE-2025-24369Anubis is a tool that allows administrators to protect bots …2.3
- CVE-2025-24370Django-Unicorn adds modern reactive component functionality …9.3
- CVE-2025-24371CometBFT is a distributed, Byzantine fault-tolerant, determi…7.1
- CVE-2025-24372CKAN is an open-source DMS (data management system) for powe…7.3
Are you affected by CVE-2025-24366?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
