aioftp is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection')
55
Medium Risk
Affected versions of this package are vulnerable to CRLF Injection in the client, which arises because the aioftp client fails to properly sanitize user input in command arguments, allowing an attacker to inject arbitrary FTP commands by embedding CR (Carriage Return) or LF (Line Feed) characters.
You are affected if you are using a version that falls within the vulnerable range.
aioftp is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 0.0.1 - 0.26.2.
Upgrade the aioftp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant