PT-2026-45697 · Sshfs · Sshfs
CVE-2026-48711
·
Published
2026-05-30
·
Updated
2026-08-28
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SSHFS versions 1.4 through 3.7.5
Description
SSHFS allows a bracketed mount source, such as
[-oProxyCommand=CMD]:/path, which is processed by the find base path() function. This function removes the brackets, resulting in a host value that starts with a hyphen and is passed as a command-line argument to ssh. If a caller provides a path-valued sftp server, ssh interprets the normalized host as an option and the server path as the destination. This sequence allows an injected ProxyCommand to execute locally as the user running SSHFS before connection or authentication occurs. The attack requires a caller or wrapper to pass an attacker-controlled mount source to SSHFS with the necessary sftp server configuration, leading to arbitrary command execution.Recommendations
Update to version 3.7.6.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sshfs