๐Ÿ” CVE Alert

CVE-2026-85756

HIGH 7.5

SSH.NET: ScpClient allows server-side RCE via default SCP path handling

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter. When an application passes an attacker-controlled path to a shell-based server, shell metacharacters not neutralized by the active IRemotePathTransformation can execute commands as the authenticated SSH user. Exploitation requires a shell-based server and a path crafted for that shell's parsing rules; non-shell servers and paths fully neutralized by the selected transformation are not affected. RemotePathTransformation.ShellQuote is available for POSIX shells, while SftpClient avoids a remote shell entirely. This issue is fixed in version 2026.0.0.

CWE CWE-78
Vendor sshnet
Product ssh.net
Published Sep 16, 2026
Last Updated Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for sshnet ssh.net

Be the first to know when new high vulnerabilities affecting sshnet ssh.net are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

sshnet / SSH.NET
< 2026.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sshnet/SSH.NET/security/advisories/GHSA-mggc-4xg6-vcxf github.com: https://github.com/sshnet/SSH.NET/commit/c66b9f8fb06c12e71761e58a577b1e796026310f github.com: https://github.com/sshnet/SSH.NET/releases/tag/2026.0.0