CVE-2026-59846

Summary

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

Workarounds

Make sure you are not executing connections with untrusted username inputs.

References