CVE-2026-48711 is a high-severity vulnerability in SSHFS, a network filesystem client for connecting to SSH servers. The vulnerability exists in versions 1.4 through 3.7.5, where an attacker can inject a ProxyCommand by providing a specially crafted mount source, leading to arbitrary command execution as the user running SSHFS. This issue has been fixed in version 3.7.6. Defenders should assess exposure a [truncated]
A vulnerability in SSHFS, a network filesystem client for connecting to SSH servers, allows a rogue SFTP server to return absolute symlink targets or relative targets containing parent-directory components. This can lead to disclosure of readable local files back to the server or writing server-controlled content to writable local files. The issue is fixed in version 3.7.6.