Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-24366

22
FAUCET Score

CVE-2025-24366 is a critical vulnerability affecting SFTPGo, an open-source file transfer solution, specifically when the optional 'rsync' command is enabled. An authenticated remote user can exploit a lack of sanitization in client-provided rsync commands to read or write files with the permissions of the SFTPGo server process. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with high impact on confidentiality, integrity, and availability, albeit with high attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
DrakkanSftpgo
>= 0.9.5, < 2.6.5CNA affected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.6
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.72%
Probability of exploitation in next 30 days
EPSS Percentile
50.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0072 is in the 46th percentile among its peer group of 1,162 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/drakkan/sftpgo/v2Fixed in: 2.6.5

Vendor Advisories (1)

goGHSA-vj7w-3m8c-6vpxhigh

SFTPGo has insufficient sanitization of user provided rsync command

Feb 7, 2025

References

github.com / drakkan/sftpgo/commit/b347ab6051f6c501da205c09315fe99cd1fa3ba1
github.com / drakkan/sftpgo/security/advisories/GHSA-vj7w-3m8c-6vpx