A AegiFlow
HIGHCVSS 7.1EPSS 0.4%

CVE-2026-48798

CVE-2026-48798 updated by NVD

Published
2026-08-12
Modified
2026-09-20
EPSS percentile
35%
Sources
github-advisory, nvd

Summary

SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to create or overwrite files anywhere writable by the client process. This issue is fixed in version 2026.0.0.

Affected packages

EcosystemPackageAffected versionsFixed versions
NuGetSSH.NET2026.0.0

Remediation: Upgrade to 2026.0.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.