CVE-2026-59995
published 2026-07-08CVE-2026-59995: sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
PriorityP429medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
EPSS
0.25%
16.7th percentile
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openbsd | openssh | < 10.4 | 10.4 |
| openbsd | openssh | — | — |
| ubuntu | openssh | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
vendor_ubuntu5.4MEDIUM
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
ghsa_unreviewed·2026-07-08
CVE-2026-59995 [MEDIUM] CWE-23 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
VulDB
OpenBSD OpenSSH up to 10.3 SFTP path traversal
vuldb·2026-07-08·CVSS 4.2
CVE-2026-59995 [MEDIUM] OpenBSD OpenSSH up to 10.3 SFTP path traversal
A vulnerability identified as critical has been detected in OpenBSD OpenSSH up to 10.3. Affected is an unknown function of the component SFTP. Performing a manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-59995. It is possible to initiate the attack remotely. There is no exploit available.
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2026-07-13·CVSS 5.4
CVE-2026-60001 [MEDIUM] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
It was discovered that OpenSSH sftp did not properly constrain the location
of downloaded files when connecting to an attacker-controlled server. An
attacker could possibly use this issue to write files to unintended
locations on the file system. (CVE-2026-59995)
It was discovered that OpenSSH scp could place files in the parent
directory of the intended destination when copying between two remote
hosts. An attacker could possibly use this issue to write files to
unintended locations. (CVE-2026-59996)
It was discovered that OpenSSH internal-sftp only recognized the first nine
command-line arguments, This could result in certain security-sensitive
arguments being ignored, contrary to expectations. (CV
Red Hat
openssh: OpenSSH: sftp client allows attacker to control downloaded file location
vendor_redhat·2026-07-08·CVSS 4.2
CVE-2026-59995 [MEDIUM] CWE-22 openssh: OpenSSH: sftp client allows attacker to control downloaded file location
openssh: OpenSSH: sftp client allows attacker to control downloaded file location
A flaw was found in OpenSSH. The `sftp` client, when used to download files from a malicious server with the 'sftp server:/path .' command, does not properly restrict where those files are saved. This allows an attacker to control the download location, potentially overwriting existing files or placing malicious files in sensitive directories on the client system, which could compromise system integrity.
Package: openssh (Red Hat Enterprise Linux 10) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 6) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 7) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 8) - Fix deferred
Package: openssh (Red Hat Enterprise Linux 9) - Fix deferre
No detection rules found.
No public exploits indexed.
2026-07-08
Published