CVE-2026-60105: Server-Side Request Forgery (SSRF) in Monsta Limited of New Zealand Monsta FTP
Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() function, which fails to detect embedded IPv4 addresses within IPv4-mapped IPv6 addresses. An unauthenticated attacker can obtain a CSRF token from the public getSystemVars endpoint and submit a fetchRemoteFile request with a source URL resolving to an IPv4-mapped address, causing the server to issue HTTP requests to internal services and write responses to an attacker-controlled FTP destination, enabling retrieval of cloud instance metadata credentials.
AI Analysis
Technical Summary
CVE-2026-60105 is a server-side request forgery vulnerability in Monsta FTP before version 2.14.5. The issue is due to an incomplete IP blocklist check in the isBlockedIP() function, which does not properly detect IPv4 addresses embedded within IPv4-mapped IPv6 addresses. An attacker without authentication can obtain a CSRF token from the public getSystemVars endpoint and use it to submit a fetchRemoteFile request with a source URL resolving to an IPv4-mapped address. This causes the server to issue HTTP requests to internal services and write responses to an attacker-controlled FTP destination, potentially exposing cloud instance metadata credentials.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to perform SSRF attacks, allowing them to make HTTP requests from the server to internal services that are otherwise inaccessible. This can lead to unauthorized access to sensitive information such as cloud instance metadata credentials, which could be used for further attacks or privilege escalation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the vulnerable fetchRemoteFile functionality if possible and monitor for suspicious requests targeting internal resources. Avoid exposing the getSystemVars endpoint publicly if feasible.
CVE-2026-60105: Server-Side Request Forgery (SSRF) in Monsta Limited of New Zealand Monsta FTP
Description
Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() function, which fails to detect embedded IPv4 addresses within IPv4-mapped IPv6 addresses. An unauthenticated attacker can obtain a CSRF token from the public getSystemVars endpoint and submit a fetchRemoteFile request with a source URL resolving to an IPv4-mapped address, causing the server to issue HTTP requests to internal services and write responses to an attacker-controlled FTP destination, enabling retrieval of cloud instance metadata credentials.
CVSS v4.0
Score 7.7high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-60105 is a server-side request forgery vulnerability in Monsta FTP before version 2.14.5. The issue is due to an incomplete IP blocklist check in the isBlockedIP() function, which does not properly detect IPv4 addresses embedded within IPv4-mapped IPv6 addresses. An attacker without authentication can obtain a CSRF token from the public getSystemVars endpoint and use it to submit a fetchRemoteFile request with a source URL resolving to an IPv4-mapped address. This causes the server to issue HTTP requests to internal services and write responses to an attacker-controlled FTP destination, potentially exposing cloud instance metadata credentials.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to perform SSRF attacks, allowing them to make HTTP requests from the server to internal services that are otherwise inaccessible. This can lead to unauthorized access to sensitive information such as cloud instance metadata credentials, which could be used for further attacks or privilege escalation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the vulnerable fetchRemoteFile functionality if possible and monitor for suspicious requests targeting internal resources. Avoid exposing the getSystemVars endpoint publicly if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-08T13:27:53.030Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4ebdf7c9d9e3dbe3bf8b56
Added to database: 07/08/2026, 21:15:35 UTC
Last enriched: 07/16/2026, 09:17:45 UTC
Last updated: 08/22/2026, 14:11:47 UTC
Views: 98
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.