Command Injection Vulnerability in SSHFS Network Filesystem Client
CVE-2026-48711
7HIGH
What is CVE-2026-48711?
SSHFS, a network filesystem client, is vulnerable to command injection due to improper handling of bracketed mount sources. In versions from 1.4 up to 3.7.6, the software can improperly parse the mount source and execute malicious commands if crafted inputs are supplied. An attacker can exploit this flaw by configuring a malicious ProxyCommand that gets executed locally, compromising the security of the user running SSHFS. This vulnerability has been addressed in version 3.7.6, emphasizing the importance of updating to secure versions.
Affected Version(s)
sshfs < 3.7.6
