Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59995

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 4.2
CVSS3: 5.4
EPSS Низкий

Описание

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
Версия до 10.4 (исключая)

EPSS

Процентиль: 15%
0.00241
Низкий

4.2 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-23

Связанные уязвимости

CVSS3: 4.2
ubuntu
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 5.4
redhat
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
msrc
24 дня назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
debian
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location o ...

CVSS3: 4.2
github
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

EPSS

Процентиль: 15%
0.00241
Низкий

4.2 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-23