CVE-2026-27699

Aliases:GHSA-5rq4-664w-9x2cDEBIAN-CVE-2026-27699CGA-6phf-q6mc-2794CGA-fh54-7mwc-xm9xCGA-h727-7vgw-w7rqCGA-hc69-5647-f5rvCGA-hr3m-mw5x-qgxmCGA-376w-2mjj-rxm5CGA-3867-gvw7-43c4CGA-4p8w-w4m4-f73hCGA-63qx-5f9v-3pmjCGA-68w3-g8h3-45gcCGA-6g37-fw6h-6637CGA-73q3-6gvc-m6q7CGA-75w5-j5g2-grwfCGA-79rw-wjqx-p8xgCGA-7ffj-rv8h-5fmfCGA-82w5-pfhx-hw83CGA-84wx-fvx7-49wjCGA-9f3g-v9qv-xfj2CGA-9h64-f7f8-9674CGA-9xf6-cmqm-757cCGA-c2pf-r8rq-m39mCGA-c8v3-w477-rgr9CGA-cm7v-g49q-4qw6CGA-fh3r-g463-cj22CGA-g42c-vm9v-225xCGA-g4cw-vj8c-h87gCGA-h589-w2x5-3pg4CGA-h8c9-m44h-33whCGA-h9mf-8w85-pcc2CGA-j9p2-45qc-f3v6CGA-jr78-244p-3ppqCGA-m5m7-p7rc-9hphCGA-m6p6-pw4r-r4jcCGA-m7x9-hx2x-x948CGA-mjpp-8pvh-qf2mCGA-mx28-327q-34mhCGA-p3qh-65p7-hj3gCGA-pf96-hcq3-m6rxCGA-phc7-2qmh-2v2fCGA-qj6q-2f37-hv2vCGA-qpqh-wwrp-g8gpCGA-r26r-q57w-v764CGA-r5g2-97rm-j3gxCGA-rj2w-55mg-7vhhCGA-rvvv-jx34-3cc4CGA-vfg4-48r2-wrgcCGA-vmgw-gq6h-x4w4CGA-vmjv-xhjx-7ggfCGA-w53h-c5x7-46c3CGA-w882-6q86-f6hcCGA-w9cp-c6c7-f486CGA-w9rp-hff2-r886CGA-wf82-q2v9-85gvCGA-wvwf-6gg4-7c7xCGA-xf9f-j9hw-rvm3CGA-xr4q-4qp3-gg9f
Advisory lineage Upstream: 0 Downstream: 3
Analyzed
Published: 25 Feb 2026, 14:58
Last modified:27 Feb 2026, 17:04

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
0.72% LOW
1% probability +0.56%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

25 Feb 2026, 14:58
Published
Vulnerability first disclosed
27 Feb 2026, 17:04
Last Modified
Vulnerability information updated

Description

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.

CVSS Metrics

  • v3.1CRITICALScore: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.72% Percentile: 52%

Techniques & Countermeasures

  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Affected Systems

  • chainguardcode-server

    < 4.106.3-r6

  • chainguardkibana-7

    all

  • chainguardkibana-8.17

    < 8.17.10-r11

  • chainguardkibana-8.17-iamguarded

    < 8.17.10-r11

  • chainguardkibana-8.18

    all

  • chainguardkibana-8.18-bitnami

    all

  • chainguardkibana-8.18-iamguarded

    all

  • chainguardkibana-8.19

    < 8.19.12-r1

  • chainguardkibana-8.19-bitnami

    < 8.19.12-r1

  • chainguardkibana-8.19-iamguarded

    < 8.19.12-r1

  • chainguardkibana-9.0

    < 9.0.8-r11

  • chainguardkibana-9.0-bitnami

    < 9.0.8-r11

  • chainguardkibana-9.0-iamguarded

    < 9.0.8-r11

  • chainguardkibana-9.1

    < 9.1.10-r6

  • chainguardkibana-9.1-iamguarded

    < 9.1.10-r6

  • chainguardkibana-9.2

    < 9.2.5-r5

  • chainguardkibana-9.2-iamguarded

    < 9.2.5-r5

  • chainguardkibana-9.3

    < 9.3.0-r2

  • chainguardkibana-9.3-iamguarded

    < 9.3.0-r2

  • chainguardlangfuse-2-worker

    < 2.95.12-r12

  • chainguardlangfuse-3-worker

    < 3.155.1-r3

  • chainguardlangfuse-fips-2-worker

    < 2.95.12-r15

  • chainguardlangfuse-fips-3-worker

    < 3.155.1-r3

  • chainguardlangfuse-fips-3.152-worker

    all

  • chainguardopensearch-dashboards-2-fips-security-dashboards-plugin

    < 2.19.4-r12

  • chainguardopensearch-dashboards-2-security-dashboards-plugin

    < 2.19.4-r12

  • chainguardopensearch-dashboards-3-fips-security-dashboards-plugin

    < 3.5.0-r2

  • chainguardopensearch-dashboards-3-security-dashboards-plugin

    < 3.5.0-r4

  • wolficode-server

    < 4.106.3-r6

  • wolfilangfuse-3-worker

    < 3.155.1-r3

  • wolfiopensearch-dashboards-3-security-dashboards-plugin

    < 3.5.0-r4

  • debiannode-proxy-agents

    < 0~2024040606-6+deb13u1 | < 0~2025070717+~cs15.2.7-1

  • Npmbasic-ftp

    < 5.2.0

  • patrickjuchlibasic-ftp

    < 5.2.0

References (7)