CVE-2026-49245: SFTPGo has stored XSS via inline parameter on public shares and user file download
The inline query parameter on the browsable-share file download and on the authenticated user file download suppressed Content-Disposition: attachment, so an HTML file stored in a share or home directory could be served as text/html and execute in SFTPGo’s web origin (stored XSS).
References
Code Behaviors & Features
Detect and mitigate CVE-2026-49245 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →