Impact
The vulnerability allows an attacker to inject shell metacharacters into a remote path that ScpClient forwards to the server’s scp command. When the chosen IRemotePathTransformation cannot neutralize these characters, the server shell executes arbitrary commands as the authenticated SSH user, compromising confidentiality and integrity. The weakness is classified as CWE‑78, indicating operating‑system command injection.
Affected Systems
SSH.NET versions earlier than 2026.0.0, when used with ScpClient on a shell‑based server, are vulnerable. The issue is fixed in 2026.0.0 and later. Applications that rely on this library and receive user‑controlled file paths must upgrade or reconfigure path handling.
Risk and Exploitability
The CVSS score of 7.5 reflects a medium to high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, exploitation requires a shell‑based server and a path crafted to that shell’s parsing rules, so the attack surface is limited but remains serious for affected deployments.
OpenCVE Enrichment
Github GHSA