CVE-2026-85756: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in sshnet SSH.NET
CVE-2026-85756 is an OS command injection vulnerability in SSH.NET's ScpClient prior to version 2026.0.0. The issue arises because caller-supplied remote paths are placed into shell commands without safe quoting, allowing shell metacharacters to execute arbitrary commands as the authenticated SSH user. This affects shell-based servers when the default RemotePathTransformation.DoubleQuote is used, which cannot safely neutralize all shell metacharacters. The vulnerability is fixed in version 2026.0.0 by improving path handling and quoting.
AI Analysis
Technical Summary
SSH.NET is a .NET library for SSH operations. In versions before 2026.0.0, the ScpClient component inserts user-supplied remote paths directly into shell commands executed on the server. The default path transformation (RemotePathTransformation.DoubleQuote) does not safely quote all shell metacharacters, leading to improper neutralization of special elements (CWE-78). An attacker controlling the remote path can craft input that executes arbitrary commands with the privileges of the authenticated SSH user, but only if the server uses a shell-based command interpreter and the path is not fully neutralized by the transformation. The issue does not affect non-shell servers or when using RemotePathTransformation.ShellQuote for POSIX shells or SftpClient which avoids shell usage. The vulnerability is resolved in SSH.NET version 2026.0.0.
Potential Impact
Successful exploitation allows an attacker who can supply a crafted remote path to execute arbitrary OS commands on the server with the privileges of the authenticated SSH user. This can lead to full compromise of the affected system's confidentiality, integrity, and availability. The attack requires a shell-based server and a vulnerable path transformation setting.
Mitigation Recommendations
Upgrade to SSH.NET version 2026.0.0 or later, where this vulnerability is fixed. Alternatively, use RemotePathTransformation.ShellQuote for POSIX shells or use SftpClient which does not invoke a remote shell. Avoid using RemotePathTransformation.DoubleQuote on shell-based servers with untrusted path input. Patch status is confirmed fixed in version 2026.0.0.
CVE-2026-85756: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in sshnet SSH.NET
Description
CVE-2026-85756 is an OS command injection vulnerability in SSH.NET's ScpClient prior to version 2026.0.0. The issue arises because caller-supplied remote paths are placed into shell commands without safe quoting, allowing shell metacharacters to execute arbitrary commands as the authenticated SSH user. This affects shell-based servers when the default RemotePathTransformation.DoubleQuote is used, which cannot safely neutralize all shell metacharacters. The vulnerability is fixed in version 2026.0.0 by improving path handling and quoting.
CVSS v3.1
Score 7.5high
Affected software
sshnet
SSH.NET
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
SSH.NET is a .NET library for SSH operations. In versions before 2026.0.0, the ScpClient component inserts user-supplied remote paths directly into shell commands executed on the server. The default path transformation (RemotePathTransformation.DoubleQuote) does not safely quote all shell metacharacters, leading to improper neutralization of special elements (CWE-78). An attacker controlling the remote path can craft input that executes arbitrary commands with the privileges of the authenticated SSH user, but only if the server uses a shell-based command interpreter and the path is not fully neutralized by the transformation. The issue does not affect non-shell servers or when using RemotePathTransformation.ShellQuote for POSIX shells or SftpClient which avoids shell usage. The vulnerability is resolved in SSH.NET version 2026.0.0.
Potential Impact
Successful exploitation allows an attacker who can supply a crafted remote path to execute arbitrary OS commands on the server with the privileges of the authenticated SSH user. This can lead to full compromise of the affected system's confidentiality, integrity, and availability. The attack requires a shell-based server and a vulnerable path transformation setting.
Mitigation Recommendations
Upgrade to SSH.NET version 2026.0.0 or later, where this vulnerability is fixed. Alternatively, use RemotePathTransformation.ShellQuote for POSIX shells or use SftpClient which does not invoke a remote shell. Avoid using RemotePathTransformation.DoubleQuote on shell-based servers with untrusted path input. Patch status is confirmed fixed in version 2026.0.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-04T14:50:16.721Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aaac81355bf5e2cf5e13881
Added to database: 09/16/2026, 16:47:15 UTC
Last enriched: 09/16/2026, 17:01:31 UTC
Last updated: 09/16/2026, 17:01:31 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.