Skip to content
archivevulnerability · 17 Sep 2026 · 17:18 UTC

GHSA-mggc-4xg6-vcxf: SSH.NET: ScpClient allows server-side RCE via default SCP path handling

VULNCVE-2026-85756source · GTH
HIGHHigh-risk vulnerability — CVSS 7.5

last 60 dispatches · spectrum

## Summary Default SCP remote-path handling places caller-supplied paths into the command that runs scp on the server. On a shell-based server that command is interpreted by a shell, so an attacker-influenced path that is not quoted to suit that shell can execute as a command as the authenticated SSH user. SSH.NET provides `ScpClient.RemotePathTransformation` to control escaping behaviour (defaulting to `RemotePathTransformation.DoubleQuote`) but cannot guarantee safety for arbitrary remote command interpreters. This is inherent to running scp over a remote shell (cf. CVE-2020-15778). …

grounded ✓primary source ↗

loading threat intel…

Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected