PT-2026-93850 · Ssh.Net · Ssh.Net

CVE-2026-85756

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SSH.NET versions prior to 2026.0.0
Description In the ScpClient component, caller-supplied remote paths are placed into the command used to run scp on the server. Because the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter, an attacker-controlled path passed to a shell-based server may allow the execution of arbitrary commands as the authenticated SSH user. This occurs when shell metacharacters are not neutralized by the active IRemotePathTransformation. Exploitation requires a shell-based server and a path specifically crafted for that shell's parsing rules. Non-shell servers and paths fully neutralized by the selected transformation are not affected.
Recommendations Update to version 2026.0.0. Use RemotePathTransformation.ShellQuote for POSIX shells. Use SftpClient instead of SCP to avoid the use of a remote shell entirely.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85756
GHSA-MGGC-4XG6-VCXF

Affected Products

Ssh.Net