PT-2026-45697 · Sshfs · Sshfs

CVE-2026-48711

·

Published

2026-05-30

·

Updated

2026-08-28

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SSHFS versions 1.4 through 3.7.5
Description SSHFS allows a bracketed mount source, such as [-oProxyCommand=CMD]:/path, which is processed by the find base path() function. This function removes the brackets, resulting in a host value that starts with a hyphen and is passed as a command-line argument to ssh. If a caller provides a path-valued sftp server, ssh interprets the normalized host as an option and the server path as the destination. This sequence allows an injected ProxyCommand to execute locally as the user running SSHFS before connection or authentication occurs. The attack requires a caller or wrapper to pass an attacker-controlled mount source to SSHFS with the necessary sftp server configuration, leading to arbitrary command execution.
Recommendations Update to version 3.7.6.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-97014
BDU:2026-12650
CVE-2026-48711
GHSA-MM85-Q63V-4476
OPENSUSE-SU-2026:10952-1
OPENSUSE-SU-2026:20915-1

Affected Products

Sshfs