Skip to main content

CVE-2026-85756: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in sshnet SSH.NET

0
High
VulnerabilityCVE-2026-85756cvecve-2026-85756cwe-78
Published: 09/16/2026 (09/16/2026, 16:31:24 UTC)
Source: CVE Database V5
Vendor/Project: sshnet
Product: SSH.NET

Description

CVE-2026-85756 is an OS command injection vulnerability in SSH.NET's ScpClient prior to version 2026.0.0. The issue arises because caller-supplied remote paths are placed into shell commands without safe quoting, allowing shell metacharacters to execute arbitrary commands as the authenticated SSH user. This affects shell-based servers when the default RemotePathTransformation.DoubleQuote is used, which cannot safely neutralize all shell metacharacters. The vulnerability is fixed in version 2026.0.0 by improving path handling and quoting.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

sshnet

SSH.NET

Affected versions
<2026.0.0
sshnet/ssh.net
pkg:nuget/sshnet/ssh.net
Affected versions
<2026.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/16/2026, 17:01:31 UTC

Technical Analysis

SSH.NET is a .NET library for SSH operations. In versions before 2026.0.0, the ScpClient component inserts user-supplied remote paths directly into shell commands executed on the server. The default path transformation (RemotePathTransformation.DoubleQuote) does not safely quote all shell metacharacters, leading to improper neutralization of special elements (CWE-78). An attacker controlling the remote path can craft input that executes arbitrary commands with the privileges of the authenticated SSH user, but only if the server uses a shell-based command interpreter and the path is not fully neutralized by the transformation. The issue does not affect non-shell servers or when using RemotePathTransformation.ShellQuote for POSIX shells or SftpClient which avoids shell usage. The vulnerability is resolved in SSH.NET version 2026.0.0.

Potential Impact

Successful exploitation allows an attacker who can supply a crafted remote path to execute arbitrary OS commands on the server with the privileges of the authenticated SSH user. This can lead to full compromise of the affected system's confidentiality, integrity, and availability. The attack requires a shell-based server and a vulnerable path transformation setting.

Mitigation Recommendations

Upgrade to SSH.NET version 2026.0.0 or later, where this vulnerability is fixed. Alternatively, use RemotePathTransformation.ShellQuote for POSIX shells or use SftpClient which does not invoke a remote shell. Avoid using RemotePathTransformation.DoubleQuote on shell-based servers with untrusted path input. Patch status is confirmed fixed in version 2026.0.0.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-09-04T14:50:16.721Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aaac81355bf5e2cf5e13881

Added to database: 09/16/2026, 16:47:15 UTC

Last enriched: 09/16/2026, 17:01:31 UTC

Last updated: 09/16/2026, 17:01:31 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses