Command Injection Vulnerability in SSHFS Network Filesystem Client
CVE-2026-48711

7HIGH

Key Information:

Vendor

Libfuse

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-48711?

SSHFS, a network filesystem client, is vulnerable to command injection due to improper handling of bracketed mount sources. In versions from 1.4 up to 3.7.6, the software can improperly parse the mount source and execute malicious commands if crafted inputs are supplied. An attacker can exploit this flaw by configuring a malicious ProxyCommand that gets executed locally, compromising the security of the user running SSHFS. This vulnerability has been addressed in version 3.7.6, emphasizing the importance of updating to secure versions.

Affected Version(s)

sshfs < 3.7.6

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.