{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ssh.net--2025.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SSH.NET (\u003c= 2025.1.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","dotnet"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eSSH.NET, a popular SSH library for .NET, contains a directory traversal vulnerability (CVE-2026-48798) in the \u003ccode\u003eScpClient\u003c/code\u003e component. When performing a recursive download of a directory, the library fails to sanitize filenames returned by the remote SCP server. A malicious or compromised SCP server can provide filenames containing directory traversal sequences (such as \u003ccode\u003e../\u003c/code\u003e) or absolute paths.\u003c/p\u003e\n\u003cp\u003eIf a client application uses \u003ccode\u003eScpClient.Download\u003c/code\u003e to pull a directory from an untrusted or compromised server, the library will construct local file paths based on these unsanitized names. This allows the attacker to write files outside of the intended target directory, potentially overwriting sensitive files such as SSH authorized keys, user profile startup scripts (e.g., .bashrc, .profile), or application configuration files. This vulnerability effectively grants the attacker the ability to perform operations with the privileges of the user running the .NET application. The issue was addressed in the project's commit history, and users are advised to upgrade to the latest version to prevent malicious path traversal during SCP operations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe impact of this vulnerability is significant, as it enables arbitrary file write capabilities on the host running the application. Successful exploitation could lead to privilege escalation or remote code execution by overwriting critical system or user files (e.g., \u003ccode\u003e~/.ssh/authorized_keys\u003c/code\u003e, \u003ccode\u003e~/.bashrc\u003c/code\u003e, or cron jobs). The threat specifically targets environments where automated, recurring backups or data synchronization tasks are performed using SSH.NET against untrusted or potentially compromised remote infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the SSH.NET NuGet package to the latest version that includes the fix for CVE-2026-48798.\u003c/li\u003e\n\u003cli\u003eAudit all applications utilizing \u003ccode\u003eSSH.NET\u003c/code\u003e to determine if \u003ccode\u003eScpClient.Download\u003c/code\u003e is used to sync data from external, non-hardened SCP servers.\u003c/li\u003e\n\u003cli\u003eReview application-level access controls for the user account executing the SSH.NET library to minimize the impact of a potential write primitive (adhere to principle of least privilege).\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual directory creation or file write events initiated by .NET applications performing network synchronization tasks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T16:48:53Z","date_published":"2026-08-12T16:48:53Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ssh-net-path-traversal/","summary":"A path traversal vulnerability in the SSH.NET ScpClient allows a malicious SCP server to write or overwrite arbitrary files on a client machine during a recursive directory download.","title":"Arbitrary File Write Vulnerability in SSH.NET ScpClient","url":"https://feed.craftedsignal.io/briefs/2026-08-ssh-net-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - SSH.NET (\u003c= 2025.1.0)","version":"https://jsonfeed.org/version/1.1"}