highCVSS 7.5Vulnerability

CVE-2026-85756

## Summary Default SCP remote-path handling places caller-supplied paths into the command that runs scp on the server. On a shell-based server that command is interpreted by a shell, so an attacker-influenced path that is not quoted to suit that shell can execute as a command as the authenticated SSH user. SSH.NET provides `ScpClient.RemotePathTransformation` to control escaping behaviour (defaulting to `RemotePathTransformation.DoubleQuote`) but cannot guarantee safety for arbitrary remote command interpreters. This is inherent to running scp over a remote shell (cf. CVE-2020-15778). ## Impact Command execution on the SSH server as the authenticated SSH user, when an application passes an attacker-influenced remote path to ScpClient against a shell-based server. Exploitation depends on conditions beyond the attacker's control: the remote server must be shell-based, and the attacker-influenced path must be crafted to defeat the quoting applied by the transformation in effect — that is, to use metacharacters that it does not neutralise (for example $(...) or backticks, which survive the default double-quoting on a POSIX shell). A path that does not meet these escaping rules, or a non-shell-based server, does not result in command execution. ## Remediation The fixed release obsoletes the constructors that silently defaulted the path transformation and adds constructors that require an explicit `IRemotePathTransformation`, so callers are required to choose one that suits their server and trust environment. For POSIX shells, the library provides `RemotePathTransformation.ShellQuote`. The legacy default (`RemotePathTransformation.DoubleQuote`) is unchanged for backwards compatibility. SCP is considered legacy and SFTP, which does not involve a remote shell, is recommended where possible (via `SftpClient`).

Properties

ghsa_id
GHSA-mggc-4xg6-vcxf
summary
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
severity
high
cvss_score
7.5
cve_id
CVE-2026-85756
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-09-17T21:32:39+00:00
is_ghsa_only
false
ghsa_published
2026-09-17T17:18:01Z
source_url
https://github.com/advisories/GHSA-mggc-4xg6-vcxf
ghsa_updated
2026-09-17T17:18:02Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]nuget/SSH.NET

AFFECTS (1)

[Software]nuget/SSH.NET

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85756 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal