CVE-2026-39983

EUVD-2026-20976
basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's protectWhitespace() helper only handles leading spaces and returns other paths unchanged, while FtpContext.send() writes the resulting command string directly to the control socket with \r\n appended. This lets attacker-controlled path strings split one intended FTP command into multiple commands. This vulnerability is fixed in 5.2.1.
CRLF Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 81.02%
Affected Products (NVD)
VendorProductVersion
patrickjuchlibasic-ftp
𝑥
< 5.2.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Developer Hub 1.8
1776784286 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.9
1777903262 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
node-proxy-agents
forky
0~2025070717+~cs15.3.8-3
fixed
sid
0~2025070717+~cs15.3.8-3
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-proxy-agents
jammy
dne
noble
needs-triage
questing
ignored
resolute
needs-triage