Patrickjuchli maintains Basic FTP, a lightweight file-transfer application whose vulnerability profile centers on resource-management and input-handling weaknesses including unbounded resource consumption, path-traversal conditions, CRLF injection, and improper pathname validation. These weakness classes are characteristic of protocols and parsers that must handle untrusted network input with minimal overhead. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Patrickjuchli over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27699CRITICAL The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server c | Feb 25, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-39983HIGH basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such | Apr 9, 2026 | 8.6 | 33 | NO | NO |
CVE-2026-41324HIGH basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remot | Apr 24, 2026 | 7.5 | 29 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Patrickjuchli.
Media articles that mention a CVE ID that affects a product developed by Patrickjuchli — matched by CVE ID, not by vendor name.