
[CVE-2026-39983: HIGH] FTP client basic-ftp for Node.js (<5.2.1) allows FTP command injection via CRLF sequences (\r\n) in file paths, exposing systems to cyber attacks. Update to 5.2.1 for a fix.#cve,CVE-2026-39983,#cybersecurity https://cvefind.com/CVE-2026-39983
Post summary
The post reports a high‑severity command injection vulnerability in basic‑ftp <5.2.1 and advises updating to version 5.2.1 to remediate the issue.
