LOWVulnerability
CVE-2026-59846
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
Properties
- severity
- LOW
- score
- 3.9
- cve_id
- CVE-2026-59846
- vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
- published_at
- 2026-07-21T13:17:18.143
- last_modified
- 2026-08-12T20:17:45.973
Related Entities (8)
AFFECTS_PRODUCT (5)
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
HAS_WEAKNESS (2)
→[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
→[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph