THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mggc-4xg6-vcxf (high) — SSH.NET: ScpClient allows server-side RCE via default SCP path handling

[GHSA] GHSA-mggc-4xg6-vcxf (high) — SSH.NET: ScpClient allows server-side RCE via default SCP path handling

medgithub_advisoriesPublished 2026-09-17

GHSA-mggc-4xg6-vcxf Severity: high CVE: CVE-2026-85756

SSH.NET: ScpClient allows server-side RCE via default SCP path handling

## Summary

Default SCP remote-path handling places caller-supplied paths into the command that runs scp on the server. On a shell-based server that command is interpreted by a shell, so an attacker-influenced path that is not quoted to suit that shell can execute as a c

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mggc-4xg6-vcxf