Shell Injection Vulnerability in libssh Affects Multiple Products
CVE-2026-59846
3.9LOW
What is CVE-2026-59846?
A vulnerability in libssh allows for injection of shell metacharacters via a maliciously crafted username in the ProxyCommand configuration. This flaw can exploit the handling of input, potentially revealing environment variables and executing unintended shell commands, leading to security breaches. As such, users of affected versions should take immediate precautions to mitigate risks.
References
CVSS V3.1
Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Mikhail Ilin and Saransh Rana for reporting this issue.