Researchers disclosed multiple serious vulnerabilities in Monsta FTP, including CVE-2025-34299 for remote code execution and CVE-2026-60105, a high-severity unauthenticated server-side request forgery flaw affecting versions through 2.14.4. The SSRF issue stems from incomplete IP blocklist validation in the fetchRemoteFile feature, allowing attackers to use IPv4-mapped IPv6 addresses such as ::ffff:169.254.169.254 to bypass protections meant to block loopback, private-network, and cloud metadata targets.
The SSRF bug lets an unauthenticated attacker obtain a CSRF token, force the server to make HTTP or HTTPS GET requests, and exfiltrate responses to an attacker-controlled FTP server, potentially exposing cloud instance metadata, internal services, and loopback-only resources. VulnCheck said Monsta FTP 2.14.5 silently fixed the SSRF issue without a security advisory, while separate reporting highlighted the remote code execution risk, leaving organizations using Monsta FTP facing both internal network exposure and possible full server compromise.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
VulnCheck disclosed CVE-2026-60105, a high-severity unauthenticated SSRF vulnerability in Monsta FTP that can be exploited using IPv4-mapped IPv6 addresses to bypass protections and reach internal or cloud metadata endpoints.
According to VulnCheck, Monsta FTP version 2.14.5 fixed an unauthenticated SSRF issue caused by incomplete IP blocklist validation in the fetchRemoteFile feature, but did so without a security advisory. The flaw affected Monsta FTP through version 2.14.4.
watchTowr Labs published research on a remote code execution vulnerability in Monsta FTP tracked as CVE-2025-34299.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
chocapikk.com
Open sourcevulncheck.com
Open sourcelabs.watchtowr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.