ʞʞıdɐɔoɥƆ[verified]@Chocapikk_Patch
CVE‑2026‑60105 was silently patched as a minor fix, with no PoC, exploit, or active exploitation reported in the text.
DFIR Lab[verified]@DFIR_LabPatch
Monsta FTP versions below 2.14.5 have an SSRF vulnerability allowing unauthenticated attackers to access internal services via IPv4‑mapped IPv6; patch to 2.14.5+ is recommended immediately.
Hugo | DevOps | Cybersecurity 🇱🇻[verified]@HugoValtersDisclosure
The Monsta FTP server version prior to 2.14.5 contains a CSRF/SSRF vulnerability that can be triggered via IPv4‑mapped IPv6 addresses. No patch exists yet; users are advised to restrict access as a temporary mitigation.
Caitlin Condon@catc0nDisclosure
A new unauthenticated SSRF vulnerability (CVE‑2026‑60105) in Monsta FTP has been disclosed, with full technical details and a proof‑of‑concept posted on the VulnCheckAI blog.
pdnuclei-bot@pdnuclei_botDisclosure
The advisory announces CVE-2026-60105—a server‑side request forgery vulnerability in Monsta FTP versions 2.14.4 and earlier—providing a link to a Project Discovery library for further details.
VulnCheck@VulnCheckAIPatch
A high‑severity unauthenticated SSRF flaw (CVE‑2026‑60105) in Monsta FTP was disclosed by VulnCheck; the vendor has quietly released a patch in version 2.14.5.