THREAT OPS › Threat News › [GHSA] GHSA-q939-rpr3-3284 (high) — SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
[GHSA] GHSA-q939-rpr3-3284 (high) — SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
GHSA-q939-rpr3-3284 Severity: high CVE: CVE-2026-48798
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
## Summary
`ScpClient.Download(string directoryName, DirectoryInfo directoryInfo)` writes files and directories using names returned by the remote SCP server during recursive downloads, with no validation that the resulting path stays insid
Indicators of compromise
- 600be0de543765995a189b5d7cd4efac5007f3cesha1
- CVE-2026-48798cve
- CVE-2019-6111cve
Original source: https://github.com/advisories/GHSA-q939-rpr3-3284