This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate gofer

Dependencies

(9 total, 2 outdated, 1 insecure)

CrateRequiredLatestStatus
 clap^4.54.6.7up to date
 data-url^0.30.3.2up to date
 dogma^0.1.90.3.0out of date
 miette^7.57.6.0up to date
 percent-encoding^2.32.3.2up to date
 ssh2^0.90.9.6up to date
 suppaftp ⚠️^612.1.1insecure
 thiserror^22.0.21up to date
 ureq^3.0.123.4.2up to date

Security Vulnerabilities

suppaftp: FTP command injection via CRLF in control channel arguments

RUSTSEC-2026-0271

Affected versions of suppaftp wrote command arguments (user name, password, paths, SITE arguments and custom commands) to the FTP control channel without validation. An argument containing a carriage return (\r) or a line feed (\n) terminated the intended command line and let a second, attacker-chosen command be sent to the server within the same authenticated session.

An application that passes untrusted input as credentials, paths or command strings to methods such as login, cwd, mkdir, rmdir, rm, rename, retr, put_file, site or custom_command can therefore be made to execute arbitrary FTP commands with the application's privileges, for example deleting files or redirecting a data connection with an injected PORT.

All three clients are affected: sync, tokio and smol, with or without TLS.

The flaw was corrected in version 10.0.2 (commit 194bdd1): every command line is validated before it is written to the wire and rejected with FtpError::ConnectionError (std::io::ErrorKind::InvalidInput) if it contains CR or LF anywhere but in the trailing terminator. As a consequence, custom_command no longer accepts several commands joined by CRLF in a single call.

Users who cannot upgrade should reject or strip \r and \n from any untrusted string before passing it to the client.