Loading market data...
← Back to CVE feed

CVE-2026-59846

LOW CVSS 3.9 View on NVD ↗

Description

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Published: Jul 21, 2026 13:17 UTC Modified: Jul 21, 2026 18:31 UTC