Description
SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter. When an application passes an attacker-controlled path to a shell-based server, shell metacharacters not neutralized by the active IRemotePathTransformation can execute commands as the authenticated SSH user. Exploitation requires a shell-based server and a path crafted for that shell's parsing rules; non-shell servers and paths fully neutralized by the selected transformation are not affected. RemotePathTransformation.ShellQuote is available for POSIX shells, while SftpClient avoids a remote shell entirely. This issue is fixed in version 2026.0.0.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to inject shell metacharacters into a remote path that ScpClient forwards to the server’s scp command. When the chosen IRemotePathTransformation cannot neutralize these characters, the server shell executes arbitrary commands as the authenticated SSH user, compromising confidentiality and integrity. The weakness is classified as CWE‑78, indicating operating‑system command injection.

Affected Systems

SSH.NET versions earlier than 2026.0.0, when used with ScpClient on a shell‑based server, are vulnerable. The issue is fixed in 2026.0.0 and later. Applications that rely on this library and receive user‑controlled file paths must upgrade or reconfigure path handling.

Risk and Exploitability

The CVSS score of 7.5 reflects a medium to high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, exploitation requires a shell‑based server and a path crafted to that shell’s parsing rules, so the attack surface is limited but remains serious for affected deployments.

Generated by OpenCVE AI on September 18, 2026 at 02:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SSH.NET to version 2026.0.0 or later to remove the vulnerable path handling logic.
  • If upgrading immediately is not an option, configure ScpClient to use RemotePathTransformation.ShellQuote when communicating with POSIX shells, or switch to SftpClient which does not invoke a remote shell.
  • Validate that any file paths passed to ScpClient are under application control or are sanitized to prevent injection of shell metacharacters.

Generated by OpenCVE AI on September 18, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mggc-4xg6-vcxf SSH.NET: ScpClient allows server-side RCE via default SCP path handling
History

Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Sshnet
Sshnet ssh.net
Vendors & Products Sshnet
Sshnet ssh.net

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter. When an application passes an attacker-controlled path to a shell-based server, shell metacharacters not neutralized by the active IRemotePathTransformation can execute commands as the authenticated SSH user. Exploitation requires a shell-based server and a path crafted for that shell's parsing rules; non-shell servers and paths fully neutralized by the selected transformation are not affected. RemotePathTransformation.ShellQuote is available for POSIX shells, while SftpClient avoids a remote shell entirely. This issue is fixed in version 2026.0.0.
Title SSH.NET: ScpClient allows server-side RCE via default SCP path handling
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:34:33.535Z

Reserved: 2026-09-04T14:50:16.721Z

Link: CVE-2026-85756

cve-icon Vulnrichment

Updated: 2026-09-16T18:23:24.367Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T17:18:16.163

Modified: 2026-09-30T17:51:36.337

Link: CVE-2026-85756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:00:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')