CVE-2026-27699
Vulnerability Summary
Timeline
Description
The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.
CVSS Metrics
- v3.1•CRITICAL•Score: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.72%• Percentile: 52%
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Affected Systems
- chainguard•code-server
< 4.106.3-r6
- chainguard•kibana-7
all
- chainguard•kibana-8.17
< 8.17.10-r11
- chainguard•kibana-8.17-iamguarded
< 8.17.10-r11
- chainguard•kibana-8.18
all
- chainguard•kibana-8.18-bitnami
all
- chainguard•kibana-8.18-iamguarded
all
- chainguard•kibana-8.19
< 8.19.12-r1
- chainguard•kibana-8.19-bitnami
< 8.19.12-r1
- chainguard•kibana-8.19-iamguarded
< 8.19.12-r1
- chainguard•kibana-9.0
< 9.0.8-r11
- chainguard•kibana-9.0-bitnami
< 9.0.8-r11
- chainguard•kibana-9.0-iamguarded
< 9.0.8-r11
- chainguard•kibana-9.1
< 9.1.10-r6
- chainguard•kibana-9.1-iamguarded
< 9.1.10-r6
- chainguard•kibana-9.2
< 9.2.5-r5
- chainguard•kibana-9.2-iamguarded
< 9.2.5-r5
- chainguard•kibana-9.3
< 9.3.0-r2
- chainguard•kibana-9.3-iamguarded
< 9.3.0-r2
- chainguard•langfuse-2-worker
< 2.95.12-r12
- chainguard•langfuse-3-worker
< 3.155.1-r3
- chainguard•langfuse-fips-2-worker
< 2.95.12-r15
- chainguard•langfuse-fips-3-worker
< 3.155.1-r3
- chainguard•langfuse-fips-3.152-worker
all
- chainguard•opensearch-dashboards-2-fips-security-dashboards-plugin
< 2.19.4-r12
- chainguard•opensearch-dashboards-2-security-dashboards-plugin
< 2.19.4-r12
- chainguard•opensearch-dashboards-3-fips-security-dashboards-plugin
< 3.5.0-r2
- chainguard•opensearch-dashboards-3-security-dashboards-plugin
< 3.5.0-r4
- wolfi•code-server
< 4.106.3-r6
- wolfi•langfuse-3-worker
< 3.155.1-r3
- wolfi•opensearch-dashboards-3-security-dashboards-plugin
< 3.5.0-r4
- debian•node-proxy-agents
< 0~2024040606-6+deb13u1 | < 0~2025070717+~cs15.2.7-1
- Npm•basic-ftp
< 5.2.0
- patrickjuchli•basic-ftp
< 5.2.0
References (7)
- https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-5rq4-664w-9x2c
- https://github.com/patrickjuchli/basic-ftp/commit/2a2a0e6514357b9eda07c2f8afbd3f04727a7cd9
- https://github.com/patrickjuchli/basic-ftp/releases/tag/v5.2.0
- https://nvd.nist.gov/vuln/detail/CVE-2026-27699
- https://github.com/patrickjuchli/basic-ftp
- https://security-tracker.debian.org/tracker/CVE-2026-27699
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27699.json