<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 01:17:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-369915</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-369915</link>
      <description>EUVD-2026-369915</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-369915</guid>
    </item>
    <item>
      <title>fkie_cve-2026-85756</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-85756</link>
      <description>&lt;p&gt;SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter. When an application passes an attacker-controlled path to a shell-based server, shell metacharacters not neutralized by the active IRemotePathTransformation can execute commands as the authenticated SSH user. Exploitation requires a shell-based server and a path crafted for that shell&amp;#39;s parsing rules; non-shell servers and paths fully neutralized by the selected transformation are not affected. RemotePathTransformation.ShellQuote is available for POSIX shells, while SftpClient avoids a remote shell entirely. This issue is fixed in version 2026.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter. When an application passes an attacker-controlled path to a shell-based server, shell metacharacters not neutralized by the active IRemotePathTransformation can execute commands as the authenticated SSH user. Exploitation requires a shell-based server and a path crafted for that shell&amp;#39;s parsing rules; non-shell servers and paths fully neutralized by the selected transformation are not affected. RemotePathTransformation.ShellQuote is available for POSIX shells, while SftpClient avoids a remote shell entirely. This issue is fixed in version 2026.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-85756</guid>
    </item>
    <item>
      <title>GHSA-mggc-4xg6-vcxf — SSH.NET: ScpClient allows server-side RCE via default SCP path handling</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mggc-4xg6-vcxf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: SSH.NET&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Default SCP remote-path handling places caller-supplied paths into the command that runs scp on the server. On a shell-based server that command is interpreted by a shell, so an attacker-influenced path that is not quoted to suit that shell can execute as a command as the authenticated SSH user. SSH.NET provides `ScpClient.RemotePathTransformation` to control escaping behaviour (defaulting to `RemotePathTransformation.DoubleQuote`) but cannot guarantee safety for arbitrary remote command interpreters. This is inherent to running scp over a remote shell (cf. CVE-2020-15778).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Command execution on the SSH server as the authenticated SSH user, when an application passes an attacker-influenced remote path to ScpClient against a shell-based server.&lt;/p&gt;
&lt;p&gt;Exploitation depends on conditions beyond the attacker&amp;#39;s control: the remote server must be shell-based, and the attacker-influenced path must be crafted to defeat the quoting applied by the transformation in effect — that is, to use metacharacters that it does not neutralise (for example $(...) or backticks, which survive the default double-quoting on a POSIX shell). A path that does not meet these escaping rules, or a non-shell-based server, does not result in command execution.&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;The fixed release obsoletes the constructors that silently defaulted the path transformation and adds constructors that require an explicit `IRemotePathTransformation`, so callers are required to choose one that suits…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: SSH.NET&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Default SCP remote-path handling places caller-supplied paths into the command that runs scp on the server. On a shell-based server that command is interpreted by a shell, so an attacker-influenced path that is not quoted to suit that shell can execute as a command as the authenticated SSH user. SSH.NET provides `ScpClient.RemotePathTransformation` to control escaping behaviour (defaulting to `RemotePathTransformation.DoubleQuote`) but cannot guarantee safety for arbitrary remote command interpreters. This is inherent to running scp over a remote shell (cf. CVE-2020-15778).&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Command execution on the SSH server as the authenticated SSH user, when an application passes an attacker-influenced remote path to ScpClient against a shell-based server.&lt;/p&gt;
&lt;p&gt;Exploitation depends on conditions beyond the attacker&amp;#39;s control: the remote server must be shell-based, and the attacker-influenced path must be crafted to defeat the quoting applied by the transformation in effect — that is, to use metacharacters that it does not neutralise (for example $(...) or backticks, which survive the default double-quoting on a POSIX shell). A path that does not meet these escaping rules, or a non-shell-based server, does not result in command execution.&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;The fixed release obsoletes the constructors that silently defaulted the path transformation and adds constructors that require an explicit `IRemotePathTransformation`, so callers are required to choose one that suits…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mggc-4xg6-vcxf</guid>
    </item>
  </channel>
</rss>
