VDB
CVE-2026-27699
CVE-2026-27699
PUBLISHED
CVSS 9.100000381469727 CRITICAL
The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.
EPSS 0.15% · 35.6th percentile
Risk Scores
CVSS v3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.15%
35.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| patrickjuchli | basic-ftp | *, < 5.2.0, 0 |
| npm | basic-ftp | 0, 0, 0 |
Timeline
- Feb 25, 2026 CVE Published
- Feb 25, 2026 PoC Published
- Feb 25, 2026 PoC Published
- Feb 26, 2026 EPSS Score
- Feb 26, 2026 PoC Published
- Feb 26, 2026 PoC Published
- Feb 27, 2026 EPSS Score
- Mar 1, 2026 EPSS Score
- Mar 2, 2026 EPSS Score
- Mar 4, 2026 EPSS Score
- Mar 5, 2026 EPSS Score
- Mar 7, 2026 EPSS Score
References
- https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-5rq4-664w-9x2c url
- https://github.com/patrickjuchli/basic-ftp/commit/2a2a0e6514357b9eda07c2f8afbd3f04727a7cd9 url
- https://github.com/patrickjuchli/basic-ftp/releases/tag/v5.2.0 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-27699 advisory
- https://github.com/patrickjuchli/basic-ftp package
- https://advisory.splunk.com/advisories/SVD-2026-0512 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0513 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0509 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0510 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0505 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0515 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0507 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0506 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0508 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0504 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0514 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0516 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0501 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0503 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0511 advisory
…and 12 more