CVE-2026-27699Disclosure(patrickjuchli / basic-ftp)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch patrickjuchli basic-ftp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written outside the intended download directory. Version 5.2.0 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • basic-ftp

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-02-25); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Products
basic-ftp

Deep dive

Activity timeline10 mentions / 6d
01122Mentions · 2026-02-25: 2Mentions · 2026-02-26: 1Mentions · 2026-02-27: 2Mentions · 2026-02-28: 2Mentions · 2026-03-02: 2Mentions · 2026-05-19: 1Patch / Workaround · 2026-02-27: 2Patch / Workaround · 2026-03-02: 1Technical Details · 2026-02-25: 2Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 2Technical Details · 2026-03-02: 202-2502-2602-2702-2803-0205-19
Signal classification3 categories
Disclosure
550.0%
Patch
330.0%
General
220.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-252
Disclosure2
2026-02-261
General1
2026-02-272
Patch2
2026-02-282
Disclosure2
2026-03-022
Disclosure1Patch1
2026-05-191
General1
Full discourse10 posts
  • Gray Hats@the_yellow_fall
    Patch

    Node.js library basic-ftp patches a critical 9.1 CVSS path traversal flaw (CVE-2026-27699). Malicious FTP servers can overwrite any file on the client machine. #NodeJS #CyberSecurity #basicftp #PathTraversal #InfoSec #CVE #Javascript #WebDev #BugBounty https://securityonline.info/critical-path-traversal-flaw-in-basic-ftp-exposes-node-js-apps-to-arbitrary-file-writes/

    Post summary

    The Node.js basic-ftp library has been patched for a critical path traversal flaw (CVE-2026-27699) that allowed malicious FTP servers to overwrite any file on the client machine.

    02022485
    10.5K followersView on X
  • Autumn Good@autumn_good_35
    General

    CVE-2025-12758 CVE-2025-64945 CVE-2026-27699 CVE-2026-27601 CVE-2026-27903 CVE-2026-27904 CVE-2026-26996 CVE-2026-25639 HPESBNW05056 rev.1 - HPE Unified OSS Console Assurance Monitoring (UOCAM), Multiple Vulnerabilities https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05056en_us&docLocale=en_US

    Post summary

    The snippet simply enumerates several CVE identifiers and a reference to an HPE support document, providing no further details on exploitation, patches, or technical aspects.

    000001.5K
    6.9K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27699 (CVSS:9.1, CRITICAL) is Analyzed. The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2..https://nvd.nist.gov/vuln/detail/CVE-2026-27699 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical path traversal vulnerability (CVE‑2026‑27699) in the basic‑ftp Node.js library, affecting versions before 5.2, with a CVSS score of 9.1.

    0000048
    173 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27699 The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A maliciou… https://www.cve.org/CVERecord?id=CVE-2026-27699 ----- Traducción: CVE-2026-27699 La … http://infoflow.cloud`

    Post summary

    CVE‑2026‑27699 is a path traversal flaw in the basic‑ftp Node.js library’s downloadToDir() method affecting versions before 5.2.0.

    0000035
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27699 The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A maliciou… https://www.cve.org/CVERecord?id=CVE-2026-27699

    Post summary

    CVE‑2026‑27699 is a path traversal vulnerability in the basic‑ftp Node.js library’s downloadToDir() method, affecting versions before 5.2.0.

    00000232
    56.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A path traversal flaw (DEBIAN-CVE-2026-27699) affects the `basic-ftp` #Nodejs library. Malicious FTP servers can exploit the `downloadToDir()` method. Update to 5.2.0 or later. #FTP #PathTraversal https://www.pulsepatch.io/posts/cve-2026-27699-basic-ftp-path-traversal

    Post summary

    The post announces a path‑traversal vulnerability (CVE-2026-27699) in the basic‑ftp Node.js library and recommends updating to 5.2.0 or later to mitigate the issue.

    0000043
    1 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Basic FTP` is affected by a path traversal vulnerability (CVE-2026-27699) in its `downloadToDir()` method. This could enable arbitrary file writes on client systems. Update to v5.2.0+. #FTP #InfoSec #CyberSecurity https://www.pulsepatch.io/posts/cve-2026-27699-basic-ftp-path-traversal

    Post summary

    Basic FTP's CVE-2026-27699 is a path traversal vulnerability that could allow arbitrary file writes, with a patch to v5.2.0+ recommended.

    0000041
    1 followersView on X
  • cvereports@_cvereports
    General

    CVE-2026-27699: FTP: File Transfer Pwnage - Analyzing CVE-2026-27699 in basic-ftp A critical Path Traversal vulnerability in the popular Node.js `basic-ftp` library allows malicious FTP servers to write arbitrary files to the client's filesystem. By c... https://cvereports.com/reports/CVE-2026-27699

    Post summary

    The post analyzes a critical path traversal flaw in the basic-ftp Node.js library that lets malicious FTP servers write arbitrary files to the client’s filesystem, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000052
    32 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27699 - Critical The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can sen... https://www.thehackerwire.com/vulnerability/CVE-2026-27699/ https://t.co/1ZlfUDWKLj

    Post summary

    The post announces a critical path traversal vulnerability in the basic‑ftp Node.js library (pre‑5.2.0) and provides technical details, but no PoC, exploit, or patch information.

    0000066
    115 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-27699 describes a **path traversal vulnerability** in the `basic-ftp` library for Node.js, specifically affecting versions prior to 5.2.0. The vulnerability resides within the `downloadToDir()` method, where a malicious FTP server can send directory listings with filenames containing directory traversal sequences (`../`). This allows an attacker to craft directory listings that, when processed by the client, cause files to be written outside the intended download directory, potentially overwriting critical files or placing malicious files in sensitive locations. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #DDoS https://cvetodo.com/cve/CVE-2026-27699

    Post summary

    The post discloses a path traversal flaw in the basic‑ftp Node.js library that allows attackers to write files outside the intended directory, but it does not mention any PoC, exploit, or patch.

    0000057
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppatrickjuchlibasic-ftp-node.js-

Explore more