{"id":"GHSA-3vcg-pv95-pq54","summary":"SFTPGo has stored XSS via inline parameter on public shares and user file download","details":"## Summary\n\nThe inline query parameter on the browsable-share file download and on the authenticated user file download suppressed Content-Disposition: attachment, so an HTML file stored in a share or home directory could be served as text/html and execute in SFTPGo's web origin (stored XSS).\n\n## Impact\n\nLow. Exploitation requires the attacker to place the file and a victim to open the crafted link — a URL the WebClient never generates, so it requires social engineering — and the practical conditions are narrow:\n\n- Session cookies are HttpOnly, so the cookie cannot be read by the injected script.\n- Authenticated shares set their own session cookie, which overwrites the victim's WebClient cookie, no account pivot. The realistic case is a public share, or a folder shared between distinct users combined with targeted social engineering.\n\nIt is a genuine trust-boundary violation (SFTPGo emits attacker-controlled content as active HTML in its own origin), hence an advisory, but the constrained preconditions and the HttpOnly mitigation keep it Low.\n\n## Patches\n\nUpgrade to v2.7.3. These endpoints now always respond with Content-Disposition: attachment; the inline parameter has been removed. See the fix commit for the full technical rationale.","aliases":["CVE-2026-49245","GO-2026-5900"],"modified":"2026-07-07T16:11:42.900493008Z","published":"2026-07-02T19:09:30Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-02T19:09:30Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/drakkan/sftpgo/security/advisories/GHSA-3vcg-pv95-pq54"},{"type":"PACKAGE","url":"https://github.com/drakkan/sftpgo"}],"affected":[{"package":{"name":"github.com/drakkan/sftpgo/v2","ecosystem":"Go","purl":"pkg:golang/github.com/drakkan/sftpgo/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.2.0"},{"fixed":"2.7.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-3vcg-pv95-pq54/GHSA-3vcg-pv95-pq54.json","last_known_affected_version_range":"\u003c= 2.7.1"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"}]}