PT-2026-93850 · Ssh.Net · Ssh.Net
CVE-2026-85756
·
Published
2026-09-16
·
Updated
2026-09-17
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SSH.NET versions prior to 2026.0.0
Description
In the
ScpClient component, caller-supplied remote paths are placed into the command used to run scp on the server. Because the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter, an attacker-controlled path passed to a shell-based server may allow the execution of arbitrary commands as the authenticated SSH user. This occurs when shell metacharacters are not neutralized by the active IRemotePathTransformation. Exploitation requires a shell-based server and a path specifically crafted for that shell's parsing rules. Non-shell servers and paths fully neutralized by the selected transformation are not affected.Recommendations
Update to version 2026.0.0.
Use
RemotePathTransformation.ShellQuote for POSIX shells.
Use SftpClient instead of SCP to avoid the use of a remote shell entirely.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ssh.Net