GHSA-5rq4-664w-9x2c
CRITICALCVE-2026-27699The basic-ftp library contains a path traversal vulnerability in the downloadToDir() method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (../) that cause files to be written outside the intended download directory.
- Affected
- < 5.2.0
- Fixed in
- 5.2.0
- Weakness
- CWE-22
- Published
- 2026-02-25
- Source
- github