Security Advisory

CVE-2026-59846

3.9
LOW

Vulnerability Description

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
Published Date July 21, 2026
Official Source NIST NVD Advisory