Vulnerability record · CVE-2024-4040 · published 22 April 2024
CVE-2024-4040: CrushFTP server-side template injection enables unauthenticated sandbox escape and RCE
Crushftp · Crushftp
CrushFTP versions before 10.7.1 and 11.1.0 contain a server-side template injection flaw that lets unauthenticated remote attackers escape the VFS sandbox. Attackers can read files outside the sandbox, bypass authentication to gain administrative access, and execute code on the server. The flaw is remotely reachable with no privileges or user interaction, making it a full server compromise risk.
Description
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0, unauthenticated network exploitation, KEV listing, and near-maximum EPSS make this an urgent patch-first issue.
What it is
CrushFTP versions before 10.7.1 and 11.1.0 contain a server-side template injection flaw that lets unauthenticated remote attackers escape the VFS sandbox. Attackers can read files outside the sandbox, bypass authentication to gain administrative access, and execute code on the server. The flaw is remotely reachable with no privileges or user interaction, making it a full server compromise risk.
Impact
An attacker gains file read outside the VFS sandbox, administrative access to CrushFTP, and remote code execution on the host. This amounts to complete server compromise.
Attack surface
Reachable over the network via the CrushFTP service; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to trigger the flaw.
Exploitation
CISA added it to KEV on 2024-04-24 with a 2024-05-01 due date, and EPSS is 0.99539 (99.9th percentile). Public exploit references exist, and press coverage describes it as an exploited zero-day.
What to do
- Upgrade CrushFTP to 10.7.1 or 11.1.0 or later immediately.
- If patching is not possible, follow vendor mitigation guidance or discontinue use of the product.
- Restrict network access to the CrushFTP service to trusted sources only.
- Rotate administrative credentials and review accounts for unauthorized changes.
- Monitor for and remove any unauthorized files or web shells left on the host.
Detection
- Review CrushFTP logs for anomalous template or expression input in requests.
- Hunt for unexpected outbound connections or child processes spawned by the CrushFTP service.
- Check for unauthorized file reads outside the configured VFS roots.
- Audit for new or modified administrative accounts and unexpected configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-4040 to the Known Exploited Vulnerabilities catalog on 24 April 2024 as "CrushFTP VFS Sandbox Escape Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 1 May 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-4040 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-4040), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.