🔐 CVE Alert

CVE-2026-93995

MEDIUM 6.5

Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write file on the server

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though class GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that authenticated SSH clients can remotely execute git commands via the JGit library on git repositories stored on the server. In CVE-2026-58624 this mechanism was restricted to only a few git commands, including "git archive" without "--output" or "-o" options such that the resulting archive would not be written on the server but instead sent back to the client over the SSH connection. The fix done for CVE-2026-58624 was insufficient as it missed removing the single-argument "-o=file.zip" version of the command parameter from the "archive" command. Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.

CWE CWE-20
Vendor apache software foundation
Product apache mina sshd
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache mina sshd

Be the first to know when new medium vulnerabilities affecting apache software foundation apache mina sshd are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

Apache Software Foundation / Apache MINA SSHD
0 < 2.20.0 3.0.0-M1 < 3.0.0-M6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread.html/k13ox2xlry38h9gh6rhmh1d9zs345clk

Credits

Ho1aAs <[email protected]>