Researchers disclosed multiple serious vulnerabilities in Monsta FTP, including CVE-2025-34299 for remote code execution and CVE-2026-60105, a high-severity unauthenticated server-side request forgery flaw affecting versions through 2.14.4. The SSRF issue stems from incomplete IP blocklist validation in the fetchRemoteFile feature, allowing attackers to use IPv4-mapped IPv6 addresses such as ::ffff:169.254.169.254 to bypass protections meant to block loopback, private-network, and cloud metadata targets.
The SSRF bug lets an unauthenticated attacker obtain a CSRF token, force the server to make HTTP or HTTPS GET requests, and exfiltrate responses to an attacker-controlled FTP server, potentially exposing cloud instance metadata, internal services, and loopback-only resources. VulnCheck said Monsta FTP 2.14.5 silently fixed the SSRF issue without a security advisory, while separate reporting highlighted the remote code execution risk, leaving organizations using Monsta FTP facing both internal network exposure and possible full server compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
VulnCheck disclosed CVE-2026-60105, a high-severity unauthenticated SSRF vulnerability in Monsta FTP that can be exploited using IPv4-mapped IPv6 addresses to bypass protections and reach internal or cloud metadata endpoints.
According to VulnCheck, Monsta FTP version 2.14.5 fixed an unauthenticated SSRF issue caused by incomplete IP blocklist validation in the fetchRemoteFile feature, but did so without a security advisory. The flaw affected Monsta FTP through version 2.14.4.
watchTowr Labs published research on a remote code execution vulnerability in Monsta FTP tracked as CVE-2025-34299.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
chocapikk.com
Open sourcevulncheck.com
Open sourcelabs.watchtowr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.