suppaftp is vulnerable to Command Injection
59
Medium Risk
The suppaftp FTP client writes command arguments to the control channel without validating them. Arguments that contain carriage return or line feed characters can terminate the intended command and add additional FTP commands onto the authenticated control connection. Affected operations are login, cwd, mkdir/rmdir, rm, rename, retr, stor, appe, list, site, and custom_command across the sync, tokio, and smol clients. The fix validates every command line before transmission and rejects any line containing CR or LF characters.
You are affected if you are using a version that falls within the vulnerable range and your application passes input into FTP command arguments.
suppaftp is vulnerable to Command Injection in versions 0.0.1 - 10.0.1.
Upgrade the suppaftp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant