Summary
CVE-2026-60105 is a high-severity server-side request forgery (SSRF) vulnerability affecting Monsta FTP in all versions before 2.14.5, published July 8, 2026 (CVSS v3.1: 8.6 HIGH). The flaw enables fully unauthenticated remote attackers to bypass the application’s internal IP blocklist via IPv4-mapped IPv6 addresses and force the server to issue HTTP requests to internal services — including cloud instance metadata endpoints — with responses exfiltrated to an attacker-controlled FTP destination.
Technical details
- Root cause: The
isBlockedIP()function in thefetchRemoteFileaction performs an incomplete IP blocklist check that fails to detect IPv4 addresses embedded within IPv4-mapped IPv6 address notation (e.g.,::ffff:127.0.0.1). Blocked IPv4 ranges — including loopback and link-local addresses — are fully bypassed when supplied in this format. - Trigger conditions: An attacker first retrieves a CSRF token from the publicly accessible
getSystemVarsendpoint, which requires no authentication. They then submit a craftedfetchRemoteFilerequest with a source URL resolving to an IPv4-mapped IPv6 address targeting an internal resource (e.g.,::ffff:169.254.169.254to reach the AWS IMDSv1 endpoint). - Attack vector: Fully remote and unauthenticated — exploitable over the network with no credentials and no user interaction required.
- Impact: The server makes HTTP requests to attacker-specified internal services and writes the responses to an attacker-controlled FTP destination. This enables exfiltration of cloud IAM credentials from instance metadata services (such as AWS IMDSv1 at
169.254.169.254), which can lead to lateral movement, privilege escalation, and full cloud environment takeover.
Affected software
- Monsta FTP (Monsta Limited of New Zealand): all versions before 2.14.5
Severity
CVSS v3.1 base score: 8.6 (HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade Monsta FTP to version 2.14.5 or later, which contains the vendor-provided fix.
- If immediate patching is not feasible:
- Restrict external network access to the Monsta FTP API endpoint (
/application/api/api.php) via a web application firewall or perimeter network controls. - Block outbound HTTP requests from the web server to cloud instance metadata IP ranges, including
169.254.169.254, at the host or network firewall level. - Restrict access to the
getSystemVarsendpoint to prevent unauthenticated CSRF token retrieval.
- Restrict external network access to the Monsta FTP API endpoint (
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

