CVE-2026-59846
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
- Published Jul 21, 2026
- CVSS 3.9 low
- 0.1% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- Multiple vulnerabilities in IBM products CERT-FR ·