← Vulnerability feed

Vulnerability record · CVE-2024-4040 · published 22 April 2024

CVE-2024-4040: CrushFTP server-side template injection enables unauthenticated sandbox escape and RCE

Crushftp · Crushftp

CrushFTP versions before 10.7.1 and 11.1.0 contain a server-side template injection flaw that lets unauthenticated remote attackers escape the VFS sandbox. Attackers can read files outside the sandbox, bypass authentication to gain administrative access, and execute code on the server. The flaw is remotely reachable with no privileges or user interaction, making it a full server compromise risk.

10.0 CVSS 3.1 Critical CISA KEV since 24 Apr 2024 EPSS 100% · top 0.1% CWE-1336 · CWE-1336CWE-94 · Code injection
10.0CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
15References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 10.0, unauthenticated network exploitation, KEV listing, and near-maximum EPSS make this an urgent patch-first issue.

What it is

CrushFTP versions before 10.7.1 and 11.1.0 contain a server-side template injection flaw that lets unauthenticated remote attackers escape the VFS sandbox. Attackers can read files outside the sandbox, bypass authentication to gain administrative access, and execute code on the server. The flaw is remotely reachable with no privileges or user interaction, making it a full server compromise risk.

Impact

An attacker gains file read outside the VFS sandbox, administrative access to CrushFTP, and remote code execution on the host. This amounts to complete server compromise.

Attack surface

Reachable over the network via the CrushFTP service; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to trigger the flaw.

Exploitation

CISA added it to KEV on 2024-04-24 with a 2024-05-01 due date, and EPSS is 0.99539 (99.9th percentile). Public exploit references exist, and press coverage describes it as an exploited zero-day.

What to do

  • Upgrade CrushFTP to 10.7.1 or 11.1.0 or later immediately.
  • If patching is not possible, follow vendor mitigation guidance or discontinue use of the product.
  • Restrict network access to the CrushFTP service to trusted sources only.
  • Rotate administrative credentials and review accounts for unauthorized changes.
  • Monitor for and remove any unauthorized files or web shells left on the host.

Detection

  • Review CrushFTP logs for anomalous template or expression input in requests.
  • Hunt for unexpected outbound connections or child processes spawned by the CrushFTP service.
  • Check for unauthorized file reads outside the configured VFS roots.
  • Audit for new or modified administrative accounts and unexpected configuration changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-4040 to the Known Exploited Vulnerabilities catalog on 24 April 2024 as "CrushFTP VFS Sandbox Escape Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 1 May 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/airbus-cert/CVE-2024-4040 ExploitThird Party Advisory
https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/ Press/Media CoverageThird Party Advisory
https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update PatchVendor Advisory
https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update PatchVendor Advisory
https://www.rapid7.com/blog/post/2024/04/23/etr-unauthenticated-crushftp-zero-day-enables-complete-server-compromise/ Third Party Advisory
https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/ ExploitIssue Tracking
https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_ftp_are_vulnerable/ Issue TrackingPatch
https://github.com/airbus-cert/CVE-2024-4040 ExploitThird Party Advisory
https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/ Press/Media CoverageThird Party Advisory
https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update PatchVendor Advisory
https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update PatchVendor Advisory
https://www.rapid7.com/blog/post/2024/04/23/etr-unauthenticated-crushftp-zero-day-enables-complete-server-compromise/ Third Party Advisory
https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/ ExploitIssue Tracking
https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_ftp_are_vulnerable/ Issue TrackingPatch
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4040 US Government Resource

Track CVE-2024-4040 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54309CrushFTP AS2 validation flaw grants remote admin accessCrushFTP 10 before 10.8.5 and 11 before 11.3.4_23 mishandle AS2 validation when the DMZ proxy feature is not in use, letting remote attackers obtain …KEVEPSS 95%analysed9.8CVE-2025-31161CrushFTP AWS4-HMAC auth bypass enables crushadmin takeoverCrushFTP 10 before 10.8.4 and 11 before 11.3.1 contains an authentication bypass in the AWS4-HMAC (S3-compatible) authorization method of its HTTP co…KEVEPSS 100%analysed9.8CVE-2024-53552Crushftp weak password recovery vulnerabilityCrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.EPSS 0.82%9.8CVE-2023-43177CrushFTP object attribute manipulation flaw allows unauthenticated compromiseCrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-913). A remote, unauthe…EPSS 82%analysed9.8CVE-2017-14035Crushftp deserialization of untrusted data vulnerabilityCrushFTP 8.x before 8.2.0 has a serialization vulnerability.EPSS 1.6%6.1CVE-2025-63419Crushftp cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects …EPSS 0.23%6.1CVE-2024-22910Crushftp cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payload.EPSS 0.50%6.1CVE-2018-18288Crushftp open redirect vulnerabilityCrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.EPSS 0.64%

Source: NIST National Vulnerability Database (record CVE-2024-4040), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.