CVE-2026-39983Patch(patrickjuchli / basic-ftp)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch patrickjuchli basic-ftp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's protectWhitespace() helper only handles leading spaces and returns other paths unchanged, while FtpContext.send() writes the resulting command string directly to the control socket with \r\n appended. This lets attacker-controlled path strings split one intended FTP command into multiple commands. This vulnerability is fixed in 5.2.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • basic-ftp

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
basic-ftp

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-09: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 104-09
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-39983: HIGH] FTP client basic-ftp for Node.js (<5.2.1) allows FTP command injection via CRLF sequences (\r\n) in file paths, exposing systems to cyber attacks. Update to 5.2.1 for a fix.#cve,CVE-2026-39983,#cybersecurity https://cvefind.com/CVE-2026-39983

    Post summary

    The post reports a high‑severity command injection vulnerability in basic‑ftp <5.2.1 and advises updating to version 5.2.1 to remediate the issue.

    0000052
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppatrickjuchlibasic-ftp-node.js-

Explore more