What is CVE-2026-5917?
A shell command injection vulnerability exists in libgit2 versions v0.27.0 through v1.9.0 when built with the libssh2 SSH backend. It allows remote attackers to execute arbitrary commands on an SSH server via a crafted repository path containing shell metacharacters. Users should update libgit2 or switch the SSH backend.
Azərbaycanca: libgit2 kitabxanasının libssh2 backend'i ilə işləyən versiyalarında qabıq əmri inyeksiyası zəifliyi aşkarlanıb. Bu boşluq uzaqdan hücumçulara SSH serverində ixtiyari əmrlər icra etməyə imkan verir. İstifadəçilərə libgit2-ni yeniləmək və ya SSH backend'ini dəyişdirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which versions of the libgit2 library are affected by the shell command injection vulnerability when using the SSH backend?
This vulnerability exists in libgit2 versions v0.27.0 through v1.9.0 when built with the libssh2 SSH backend.
What is recommended to protect against the CVE-2026-5917 vulnerability?
Users are advised to update the libgit2 library or switch the SSH backend they are using.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.