A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbitrary files outside the configured FTP root directory. The flaw is due to insufficient sanitation of user-supplied file paths in the FTP GET and PUT command handlers. Exploitation is possible by submitting traversal sequences during FTP operations, enabling access to system-sensitive files. This issue affects only the Windows version of ColoradoFTP.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-22",
"CWE-306",
"CWE-552"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/34xxx/CVE-2025-34110.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "1.3 Build 8"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"last_affected": "1.3 Build 8"
}
],
"source": "CPE_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-34110.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"251145532788171280305768876642995824501",
"7093707141429545515907161534099995653",
"312538698378582257593424737016874255716"
],
"threshold": 0.9
},
"id": "CVE-2025-34110-147b8826",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://bitbucket.org/nolife/coloradoftp@16a60c4a74ef477cd8c16ca82442eaab2fbe8c86",
"target": {
"file": "coloradoftp/plugins/xmlfs/src/main/java/com/coldcore/coloradoftp/plugin/xmlfs/resolver/GenericVirtualPathResolver.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "30800469746312930370171075578529644280",
"length": 597
},
"id": "CVE-2025-34110-9048897e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://bitbucket.org/nolife/coloradoftp@16a60c4a74ef477cd8c16ca82442eaab2fbe8c86",
"target": {
"file": "coloradoftp/plugins/xmlfs/src/main/java/com/coldcore/coloradoftp/plugin/xmlfs/resolver/GenericVirtualPathResolver.java",
"function": "fixVirtualParentRefs"
}
}
]
"2026-08-12T15:13:28Z"