CVE-2026-27699

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:patrickjuchli:basic-ftp:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-02-25 15:20

Updated : 2026-06-17 10:27


NVD link : CVE-2026-27699

Mitre link : CVE-2026-27699

CVE.ORG link : CVE-2026-27699


JSON object : View

Products Affected

patrickjuchli

  • basic-ftp
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')