CVE-2026-59846

Published: July 22, 2026Last modified: July 29, 2026

Description

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

Severity score breakdown

ParameterValue
Base score3.9
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibsshFixed (0.11.5-r0)
25 LTSlibsshFixed (0.11.5-r0)
StreamlibsshFixed (0.12.1-r0)

References

ON THIS PAGE