CrushFTP VFS Sandbox Escape: Zero-Trust Patch Confusion in File Transfer
On April 19-20, 2024, CrushFTP shipped emergency fixes for CVE-2024-4040 — an unauthenticated escape from the virtual file system sandbox that exposed arbitrary host files, including the credential-stuffed configuration that anchors enterprise partner integrations. Exploitation followed within days, CISA listed it April 30, and a chaotic trail of interim builds left customers arguing about version numbers mid-fire. This account covers the traversal-to-escape chain, the mainserv credential hunt, and the hard lessons of small-vendor emergency patching.
