PatchSiren

libfuse CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH libfuse CVE published 2026-08-19

CVE-2026-48711

CVE-2026-48711 is a high-severity vulnerability in SSHFS, a network filesystem client for connecting to SSH servers. The vulnerability exists in versions 1.4 through 3.7.5, where an attacker can inject a ProxyCommand by providing a specially crafted mount source, leading to arbitrary command execution as the user running SSHFS. This issue has been fixed in version 3.7.6. Defenders should assess exposure a [truncated]

CRITICAL libfuse CVE published 2026-08-19

CVE-2026-47187

A vulnerability in SSHFS, a network filesystem client for connecting to SSH servers, allows a rogue SFTP server to return absolute symlink targets or relative targets containing parent-directory components. This can lead to disclosure of readable local files back to the server or writing server-controlled content to writable local files. The issue is fixed in version 3.7.6.