What is CVE-2026-48798?
CVE-2026-48798 is a vulnerability in the SSH.NET library for .NET, affecting version 2025.1.0 and earlier. The ScpClient.Download function does not validate file and directory names from a remote SCP server, allowing a path traversal attack where a malicious server can write files outside the intended local directory. Users should update SSH.NET to the latest patched version.
Azərbaycanca: CVE-2026-48798, .NET üçün SSH.NET kitabxanasının 2025.1.0 və əvvəlki versiyalarında tapılan boşluqdur. ScpClient.Download funksiyası uzaq SCP serverdən gələn fayl və qovluq adlarını düzgün yoxlamadığı üçün, təcavüzkar path traversal hücumu ilə lokal sistemdə ixtiyari fayl yaza bilər. İstifadəçilər SSH.NET kitabxanasını ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which .NET library does CVE-2026-48798 affect?
This vulnerability affects the SSH.NET library.
What type of attack does CVE-2026-48798 allow?
This vulnerability allows a path traversal attack, enabling an attacker to write arbitrary files outside the intended local directory.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.