
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25683 is a denial of service (DoS) vulnerability in FileZilla Client 3.40.0 affecting the application's local search functionality. A local attacker can crash the application by supplying a malformed path string in the search directory field. The vulnerability was formally published to the NVD and GitHub Advisory Database on April 5, 2026, and assigned a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory).
The vulnerability is classified under CWE-532 (Insertion of Sensitive Information into Log File) by the GitHub Advisory Database, though Feedly's estimate also associates it with CWE-125 (Out-of-bounds Read), suggesting the crash may involve improper memory access when processing an oversized or malformed path string (GitHub Advisory). Exploitation requires a local attacker to enter a crafted path string — specifically 384 'A' characters followed by 'BBBB' and 'CCCC' sequences — into the search directory field and initiate a local search operation. A public proof-of-concept Python script on Exploit-DB automates generation of this malicious payload by writing the crafted string to a file (Exploit-DB). No network access or elevated privileges are required to trigger the crash.
Successful exploitation causes the FileZilla Client application to crash, resulting in a complete loss of availability for the affected application instance. There is no impact on confidentiality or integrity, and the vulnerability is scoped to the vulnerable system only with no lateral movement potential. The impact is limited to disruption of the FTP client session for the affected local user (GitHub Advisory).
buff.txt) containing a crafted path: a forward slash followed by 384 'A' characters, then 'BBBB', then 'CCCC' (e.g., /AAAA...AAAABBBBCCCC).buff.txt and paste it into the search directory field.filezilla.exe (Windows) or filezilla (Linux) process without user-initiated close action.buff.txt or similar containing a string of 384+ repeated characters followed by 'BBBB' and 'CCCC' in user-accessible directories, indicative of PoC payload generation (Exploit-DB).Users should upgrade FileZilla Client to a version beyond 3.40.0, as the vulnerability is specific to that release. A patch is referenced via GitHub Advisory GHSA-g5wj-4965-6q9m, though specific patched version numbers are not explicitly listed in available advisories (GitHub Advisory). As a temporary workaround, administrators can restrict local user access to FileZilla Client or advise users to avoid using the local search functionality until an upgrade is applied.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."