NUGET · AUGUST 2026 · EARLY WARNING

ssh.net NuGet Package Vulnerability: Arbitrary File Write Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
ssh.net (nuget)
Affected versions
>= 2.2.0, <= 2.2.0 or >= sshd-2.2.0, <= sshd-2.2.0 or >= V_7_9_P1, <= V_7_9_P1 or >= V_7_8_P1, <= V_7_8_P1 or >= V_7_7_P1, <= V_7_7_P1 or >= V_7_6_P1, <= V_7_6_P1 or >= V_7_5_P1, <= V_7_5_P1 or >= V_7_4_P1, <= V_7_4_P1 or >= V_7_3_P1, <= V_7_3_P1 or >= V_7_2_P1, <= V_7_2_P1 or >= V_7_1_P1, <= V_7_1_P1 or >= V_7_0_P1, <= V_7_0_P1 or >= V_6_9_P1, <= V_6_9_P1 or >= V_6_8_P1, <= V_6_8_P1 or >= V_6_6_P1, <= V_6_6_P1 or >= V_6_5_P1, <= V_6_5_P1 or >= V_6_2_P1, <= V_6_2_P1 or >= V_6_1_P1, <= V_6_1_P1 or >= V_6_0_P1, <= V_6_0_P1 or >= V_5_7_P1, <= V_5_7_P1 or >= V_5_5_P1, <= V_5_5_P1 or >= V_5_2_P1, <= V_5_2_P1 or >= V_5_1_P1, <= V_5_1_P1 or >= V_5_0_P1, <= V_5_0_P1 or >= V_4_2_P1, <= V_4_2_P1 or >= V_3_9_P1, <= V_3_9_P1 or >= V_3_8_P1, <= V_3_8_P1 or >= AFTER_KRB5_GSSAPI_MERGE, <= AFTER_KRB5_GSSAPI_MERGE or >= BEFORE_KRB5_GSSAPI_MERGE, <= BEFORE_KRB5_GSSAPI_MERGE or >= POST_KRB4_REMOVAL, <= POST_KRB4_REMOVAL or >= PRE_KRB4_REMOVAL, <= PRE_KRB4_REMOVAL or >= AFTER_FREEBSD_PAM_MERGE, <= AFTER_FREEBSD_PAM_MERGE or >= BEFORE_FREEBSD_PAM_MERGE, <= BEFORE_FREEBSD_PAM_MERGE or >= V_3_6_1_P1, <= V_3_6_1_P1 or >= V_3_4_P1, <= V_3_4_P1 or >= V_3_2_2_P1, <= V_3_2_2_P1 or >= PRE_SW_KRBV, <= PRE_SW_KRBV or >= V_3_1_P1, <= V_3_1_P1 or >= V_3_0_1_P1, <= V_3_0_1_P1 or >= V_3_0_P1, <= V_3_0_P1 or >= V_2_5_2_P1, <= V_2_5_2_P1 or >= V_2_5_1_P2, <= V_2_5_1_P2 or >= V_2_5_1_P1, <= V_2_5_1_P1 or >= V_2_5_0_P1, <= V_2_5_0_P1 or >= PRE-REORDER, <= PRE-REORDER or >= V_2_3_0_P1, <= V_2_3_0_P1 or >= PRE_CYGWIN_MERGE, <= PRE_CYGWIN_MERGE or >= V_2_2_0_P1, <= V_2_2_0_P1 or >= V_2_1_1_P4, <= V_2_1_1_P4 or >= V_2_1_1_P3, <= V_2_1_1_P3 or >= ABOUT_TO_ADD_INET_ATON, <= ABOUT_TO_ADD_INET_ATON or >= V_2_1_1_P2, <= V_2_1_1_P2 or >= V_2_1_1_P1, <= V_2_1_1_P1 or >= PRE_NEW_LOGIN_CODE, <= PRE_NEW_LOGIN_CODE or >= V_2_1_0_P3, <= V_2_1_0_P3 or >= V_2_1_0_P2, <= V_2_1_0_P2 or >= V_2_1_0_P1, <= V_2_1_0_P1 or >= V_2_1_0, <= V_2_1_0 or >= V_2_0_0_BETA2, <= V_2_0_0_BETA2 or >= V_2_0_0_BETA1, <= V_2_0_0_BETA1 or >= V_2_0_0_TEST1, <= V_2_0_0_TEST1 or >= V_1_2_3_TEST3, <= V_1_2_3_TEST3 or >= V_1_2_3_TEST2, <= V_1_2_3_TEST2 or >= V_1_2_3_TEST1, <= V_1_2_3_TEST1 or >= V_1_2_3, <= V_1_2_3 or >= V_1_2_3_PRE5, <= V_1_2_3_PRE5 or >= V_1_2_3_PRE4, <= V_1_2_3_PRE4 or >= V_1_2_3_PRE3, <= V_1_2_3_PRE3 or >= V_1_2_3_PRE2, <= V_1_2_3_PRE2 or >= V_1_2_3_PRE1, <= V_1_2_3_PRE1 or >= V_1_2_2_P1, <= V_1_2_2_P1 or >= V_1_2_2, <= V_1_2_2 or >= V_1_2_2_PRE29, <= V_1_2_2_PRE29 or >= V_1_2_2_PRE28, <= V_1_2_2_PRE28 or >= V_1_2_1_PRE27, <= V_1_2_1_PRE27 or >= V_1_2_1_PRE26, <= V_1_2_1_PRE26 or >= PRE_IPV6, <= PRE_IPV6 or >= V_1_2_1_PRE25, <= V_1_2_1_PRE25 or >= V_1_2_1_PRE24, <= V_1_2_1_PRE24 or >= V_1_2_1_PRE23, <= V_1_2_1_PRE23 or >= V_1_2_1_PRE22, <= V_1_2_1_PRE22 or >= PRE_FIXPATHS_INTEGRATION, <= PRE_FIXPATHS_INTEGRATION or >= V_1_2_1_PRE21, <= V_1_2_1_PRE21 or >= V_1_2_1_PRE20, <= V_1_2_1_PRE20 or >= V_1_2_1_PRE19, <= V_1_2_1_PRE19 or >= PRE_HPUX_INTEGRATION, <= PRE_HPUX_INTEGRATION or >= V_1_2_1_PRE18, <= V_1_2_1_PRE18 or >= V_1_2PRE17, <= V_1_2PRE17 or >= V_1_2_PRE16, <= V_1_2_PRE16 or >= V_1_2_PRE15, <= V_1_2_PRE15 or >= V_1_2_PRE14, <= V_1_2_PRE14 or >= V_1_2_PRE13, <= V_1_2_PRE13 or >= V_1_2_PRE12, <= V_1_2_PRE12 or >= V_1_2_PRE11, <= V_1_2_PRE11 or >= V_1_2_PRE10, <= V_1_2_PRE10 or >= V_1_2_PRE9, <= V_1_2_PRE9 or >= V_1_2_PRE8, <= V_1_2_PRE8 or >= V_1_2_PRE7, <= V_1_2_PRE7 or >= V_1_2_PRE6, <= V_1_2_PRE6 or >= V_1_2_PRE5, <= V_1_2_PRE5 or >= V_1_2_PRE4, <= V_1_2_PRE4 or >= PRE_DAN_PATCH_MERGE, <= PRE_DAN_PATCH_MERGE
Patched version
Not yet available
CVE-2019-6111GHSA-Q939-RPR3-3284GHSA-JR78-HFW4-XP7G

An early warning has been issued for a high-severity vulnerability in the ssh.net NuGet package. This vulnerability allows arbitrary file write via server-controlled SCP filenames, potentially leading to remote code execution.

What happened

The ssh.net NuGet package's ScpClient.Download method reportedly allows arbitrary file write via server-controlled SCP filenames. This vulnerability could enable a malicious server to cause the client to write files outside the intended directory, potentially leading to remote code execution. The vulnerability is under investigation and has not yet been exploited in the wild.

Affected versions of ssh.net include a wide range of versions from 2.2.0 to V_1_2_PRE4 and PRE_DAN_PATCH_MERGE. The exact version range is extensive, covering numerous patch levels and pre-release versions.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If ssh.net is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using any version of ssh.net from 2.2.0 to V_1_2_PRE4 and PRE_DAN_PATCH_MERGE.

What should I do right now?

Upgrade to the latest version of ssh.net that includes the fix for this vulnerability and monitor the primary sources for updates.

Has this been exploited in the wild?

No, this vulnerability has not yet been exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats