ssh.net NuGet Package Vulnerability: Critical CVE Warning
- Severity
- HIGH
- Affected component
- ssh.net (nuget)
- Affected versions
- >= 2.2.0, <= 2.2.0 or >= sshd-2.2.0, <= sshd-2.2.0 or >= V_7_9_P1, <= V_7_9_P1 or >= V_7_8_P1, <= V_7_8_P1 or >= V_7_7_P1, <= V_7_7_P1 or >= V_7_6_P1, <= V_7_6_P1 or >= V_7_5_P1, <= V_7_5_P1 or >= V_7_4_P1, <= V_7_4_P1 or >= V_7_3_P1, <= V_7_3_P1 or >= V_7_2_P1, <= V_7_2_P1 or >= V_7_1_P1, <= V_7_1_P1 or >= V_7_0_P1, <= V_7_0_P1 or >= V_6_9_P1, <= V_6_9_P1 or >= V_6_8_P1, <= V_6_8_P1 or >= V_6_6_P1, <= V_6_6_P1 or >= V_6_5_P1, <= V_6_5_P1 or >= V_6_2_P1, <= V_6_2_P1 or >= V_6_1_P1, <= V_6_1_P1 or >= V_6_0_P1, <= V_6_0_P1 or >= V_5_7_P1, <= V_5_7_P1 or >= V_5_5_P1, <= V_5_5_P1 or >= V_5_2_P1, <= V_5_2_P1 or >= V_5_1_P1, <= V_5_1_P1 or >= V_5_0_P1, <= V_5_0_P1 or >= V_4_2_P1, <= V_4_2_P1 or >= V_3_9_P1, <= V_3_9_P1 or >= V_3_8_P1, <= V_3_8_P1 or >= AFTER_KRB5_GSSAPI_MERGE, <= AFTER_KRB5_GSSAPI_MERGE or >= BEFORE_KRB5_GSSAPI_MERGE, <= BEFORE_KRB5_GSSAPI_MERGE or >= POST_KRB4_REMOVAL, <= POST_KRB4_REMOVAL or >= PRE_KRB4_REMOVAL, <= PRE_KRB4_REMOVAL or >= AFTER_FREEBSD_PAM_MERGE, <= AFTER_FREEBSD_PAM_MERGE or >= BEFORE_FREEBSD_PAM_MERGE, <= BEFORE_FREEBSD_PAM_MERGE or >= V_3_6_1_P1, <= V_3_6_1_P1 or >= V_3_4_P1, <= V_3_4_P1 or >= V_3_2_2_P1, <= V_3_2_2_P1 or >= PRE_SW_KRBV, <= PRE_SW_KRBV or >= V_3_1_P1, <= V_3_1_P1 or >= V_3_0_1_P1, <= V_3_0_1_P1 or >= V_3_0_P1, <= V_3_0_P1 or >= V_2_5_2_P1, <= V_2_5_2_P1 or >= V_2_5_1_P2, <= V_2_5_1_P2 or >= V_2_5_1_P1, <= V_2_5_1_P1 or >= V_2_5_0_P1, <= V_2_5_0_P1 or >= PRE-REORDER, <= PRE-REORDER or >= V_2_3_0_P1, <= V_2_3_0_P1 or >= PRE_CYGWIN_MERGE, <= PRE_CYGWIN_MERGE or >= V_2_2_0_P1, <= V_2_2_0_P1 or >= V_2_1_1_P4, <= V_2_1_1_P4 or >= V_2_1_1_P3, <= V_2_1_1_P3 or >= ABOUT_TO_ADD_INET_ATON, <= ABOUT_TO_ADD_INET_ATON or >= V_2_1_1_P2, <= V_2_1_1_P2 or >= V_2_1_1_P1, <= V_2_1_1_P1 or >= PRE_NEW_LOGIN_CODE, <= PRE_NEW_LOGIN_CODE or >= V_2_1_0_P3, <= V_2_1_0_P3 or >= V_2_1_0_P2, <= V_2_1_0_P2 or >= V_2_1_0_P1, <= V_2_1_0_P1 or >= V_2_1_0, <= V_2_1_0 or >= V_2_0_0_BETA2, <= V_2_0_0_BETA2 or >= V_2_0_0_BETA1, <= V_2_0_0_BETA1 or >= V_2_0_0_TEST1, <= V_2_0_0_TEST1 or >= V_1_2_3_TEST3, <= V_1_2_3_TEST3 or >= V_1_2_3_TEST2, <= V_1_2_3_TEST2 or >= V_1_2_3_TEST1, <= V_1_2_3_TEST1 or >= V_1_2_3, <= V_1_2_3 or >= V_1_2_3_PRE5, <= V_1_2_3_PRE5 or >= V_1_2_3_PRE4, <= V_1_2_3_PRE4 or >= V_1_2_3_PRE3, <= V_1_2_3_PRE3 or >= V_1_2_3_PRE2, <= V_1_2_3_PRE2 or >= V_1_2_3_PRE1, <= V_1_2_3_PRE1 or >= V_1_2_2_P1, <= V_1_2_2_P1 or >= V_1_2_2, <= V_1_2_2 or >= V_1_2_2_PRE29, <= V_1_2_2_PRE29 or >= V_1_2_2_PRE28, <= V_1_2_2_PRE28 or >= V_1_2_1_PRE27, <= V_1_2_1_PRE27 or >= V_1_2_1_PRE26, <= V_1_2_1_PRE26 or >= PRE_IPV6, <= PRE_IPV6 or >= V_1_2_1_PRE25, <= V_1_2_1_PRE25 or >= V_1_2_1_PRE24, <= V_1_2_1_PRE24 or >= V_1_2_1_PRE23, <= V_1_2_1_PRE23 or >= V_1_2_1_PRE22, <= V_1_2_1_PRE22 or >= PRE_FIXPATHS_INTEGRATION, <= PRE_FIXPATHS_INTEGRATION or >= V_1_2_1_PRE21, <= V_1_2_1_PRE21 or >= V_1_2_1_PRE20, <= V_1_2_1_PRE20 or >= V_1_2_1_PRE19, <= V_1_2_1_PRE19 or >= PRE_HPUX_INTEGRATION, <= PRE_HPUX_INTEGRATION or >= V_1_2_1_PRE18, <= V_1_2_1_PRE18 or >= V_1_2PRE17, <= V_1_2PRE17 or >= V_1_2_PRE16, <= V_1_2_PRE16 or >= V_1_2_PRE15, <= V_1_2_PRE15 or >= V_1_2_PRE14, <= V_1_2_PRE14 or >= V_1_2_PRE13, <= V_1_2_PRE13 or >= V_1_2_PRE12, <= V_1_2_PRE12 or >= V_1_2_PRE11, <= V_1_2_PRE11 or >= V_1_2_PRE10, <= V_1_2_PRE10 or >= V_1_2_PRE9, <= V_1_2_PRE9 or >= V_1_2_PRE8, <= V_1_2_PRE8 or >= V_1_2_PRE7, <= V_1_2_PRE7 or >= V_1_2_PRE6, <= V_1_2_PRE6 or >= V_1_2_PRE5, <= V_1_2_PRE5 or >= V_1_2_PRE4, <= V_1_2_PRE4 or >= PRE_DAN_PATCH_MERGE, <= PRE_DAN_PATCH_MERGE
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the ssh.net NuGet package. This vulnerability could allow a malicious SCP server to write files outside the intended download directory, potentially leading to remote code execution or privilege escalation.
What happened
The vulnerability affects the ScpClient.Download method in the ssh.net NuGet package. A malicious SCP server could exploit this to write files outside the intended download directory. This issue is similar to OpenSSH CVE-2019-6111 but includes directory traversal capability. The vulnerability was first flagged on 2026-08-12T15:19:10+00:00.
Affected versions of ssh.net include a wide range of versions from 2.2.0 to V_1_2_PRE4 and various other identifiers. The vulnerability has not been exploited in the wild as of the latest reports. It is recommended to upgrade to the latest version of ssh.net that includes the fix for this vulnerability.
What to do about it
- Identify if your project uses any affected versions of the ssh.net NuGet package.
- Upgrade to the latest version of ssh.net that includes the fix for this vulnerability.
- Monitor the primary sources for updates on the vulnerability and any additional fixes that may be released.
- Review your SCP server configurations to ensure they are secure and not susceptible to similar attacks.
- Consider implementing additional security measures to protect against potential remote code execution or privilege escalation attacks.
How 0Day would have caught this
ssh.net is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if your project uses any version of ssh.net NuGet package from 2.2.0 to V_1_2_PRE4 and various other identifiers as listed in the affected components section.
What should I do right now?
Immediately identify if your project uses any affected versions of the ssh.net NuGet package and upgrade to the latest version that includes the fix for this vulnerability.
Has an official fix been published?
No official fix has been published yet. Monitor the primary sources for updates on the vulnerability and any additional fixes that may be released.
What are the potential risks of this vulnerability?
The potential risks include remote code execution or privilege escalation due to a malicious SCP server writing files outside the intended download directory.