CVE-2026-48798 with a CVSS score of 7.1 is a path traversal vulnerability affecting the SSH.NET framework. The flaw exists within the ScpClient.Download method, which improperly handles file and directory names supplied by the remote SCP server during recursive download operations without adequate validation. An attacker can exploit this issue by controlling a malicious, compromised, or man-in-the-middle SCP server that responds to download requests with path traversal sequences such as ../ or absolute paths designed to escape the intended directory. Successful exploitation allows the attacker to write or overwrite arbitrary files on the client system wherever the running process has write permissions. This could result in severe business impacts, including remote code execution, persistence, or privilege escalation through modification of sensitive files such as SSH authorized keys, shell configuration files, cron entries, or application binaries. Exploitation requires the victim to initiate a recursive directory download from an attacker-controlled SCP server.
We recommend you to update SSH.NET to version 2026.0.0 or later.[/subscribe_to_unlock_form]
CVE-2026-48798 with a CVSS score of 7.1 is a path traversal vulnerability affecting the SSH.NET framework. The flaw exists within the ScpClient.Download method, which improperly handles file and directory names supplied by the remote SCP server during recursive download operations without adequate validation. An attacker can exploit this issue by controlling a malicious, compromised, or man-in-the-middle SCP server that responds to download requests with path traversal sequences such as ../ or absolute paths designed to escape the intended directory. Successful exploitation allows the attacker to write or overwrite arbitrary files on the client system wherever the running process has write permissions. This could result in severe business impacts, including remote code execution, persistence, or privilege escalation through modification of sensitive files such as SSH authorized keys, shell configuration files, cron entries, or application binaries. Exploitation requires the victim to initiate a recursive directory download from an attacker-controlled SCP server.
We recommend you to update SSH.NET to version 2026.0.0 or later.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]