CVE-2026-60105Disclosure

LOWCVSS 7.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() function, which fails to detect embedded IPv4 addresses within IPv4-mapped IPv6 addresses. An unauthenticated attacker can obtain a CSRF token from the public getSystemVars endpoint and submit a fetchRemoteFile request with a source URL resolving to an IPv4-mapped address, causing the server to issue HTTP requests to internal services and write responses to an attacker-controlled FTP destination, enabling retrieval of cloud instance metadata credentials.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-07-14); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-07-09: 1Mentions · 2026-07-11: 1Mentions · 2026-07-14: 3Mentions · 2026-09-09: 1PoC Mentioned / Linked · 2026-07-14: 1PoC Mentioned / Linked · 2026-09-09: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-14: 2Technical Details · 2026-07-09: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-14: 2Technical Details · 2026-09-09: 107-0907-1107-1409-09
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-091
Disclosure1
2026-07-111
Patch1
2026-07-143
Disclosure1Patch2
2026-09-091
Disclosure1
Full discourse6 posts
  • Caitlin Condon@catc0n
    Disclosure

    New vuln disclosure out from @Chocapikk_ today: CVE-2026-60105 is an unauthenticated SSRF in Monsta FTP that makes for a nice primitive. Full details + PoC out on the @VulnCheckAI blog now. https://www.vulncheck.com/blog/monsta-ftp-ssrf-ipv6-blocklist-bypass

    Post summary

    A new unauthenticated SSRF vulnerability (CVE‑2026‑60105) in Monsta FTP has been disclosed, with full technical details and a proof‑of‑concept posted on the VulnCheckAI blog.

    1411992.9K
    3.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-60105 - high 🚨 Monsta FTP <= 2.14.4 - Unauthenticated SSRF via IPv6 Blocklist Bypass > Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-60105 @pdnuclei #NucleiTemplates ...

    Post summary

    The advisory announces CVE-2026-60105—a server‑side request forgery vulnerability in Monsta FTP versions 2.14.4 and earlier—providing a link to a Project Discovery library for further details.

    13085745
    1.3K followersView on X
  • VulnCheck@VulnCheckAI
    Patch

    Today, VulnCheck disclosed CVE-2026-60105, a high-severity unauthenticated flaw in Monsta FTP that could expose cloud metadata and internal services. Monsta FTP silently patched the issue in 2.14.5 under “Minor bugs and fixes.” Read the full report: https://vulncheck.com/blog/monsta-ftp-ssrf-ipv6-blocklist-bypass

    Post summary

    A high‑severity unauthenticated SSRF flaw (CVE‑2026‑60105) in Monsta FTP was disclosed by VulnCheck; the vendor has quietly released a patch in version 2.14.5.

    070811.2K
    880 followersView on X
  • ʞʞıdɐɔoɥƆ@Chocapikk_
    Patch

    A blocklist that speaks fluent IPv4 and barely speaks IPv6. No shells this time. Silently patched as "Minor bugs and fixes" though. CVE-2026-60105

    Post summary

    CVE‑2026‑60105 was silently patched as a minor fix, with no PoC, exploit, or active exploitation reported in the text.

    02060970
    4.1K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH Severity: CVE-2026-60105 (CVSS 8.6) Monsta FTP <2.14.5 has SSRF flaw allowing unauthenticated attackers to access internal services & cloud metadata via IPv4-mapped IPv6 bypass. Patch immediately to 2.14.5+ #CVE #Vulnerability #PatchNow https://t.co/jIxnbILNHw

    Post summary

    Monsta FTP versions below 2.14.5 have an SSRF vulnerability allowing unauthenticated attackers to access internal services via IPv4‑mapped IPv6; patch to 2.14.5+ is recommended immediately.

    0000055
    71 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-60105 - #CSRF in Monsta #FTP before 2.14.5. Unauthenticated attackers can bypass IP blocklist via IPv4-mapped IPv6 addresses to trigger #SSRF. #CVSS 8.6. Patch unavailable; restrict access now. #CVEAlert #infosec #cybersecurity #hackers #devops #networking #devsecops https://www.valtersit.com/cve/CVE-2026-60105

    Post summary

    The Monsta FTP server version prior to 2.14.5 contains a CSRF/SSRF vulnerability that can be triggered via IPv4‑mapped IPv6 addresses. No patch exists yet; users are advised to restrict access as a temporary mitigation.

    0000054
    974 followersView on X

Explore more