PatchSiren

sshnet CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH sshnet CVE published 2026-08-18

CVE-2026-48798

CVE-2026-48798 is a high-severity vulnerability in SSH.NET, a Secure Shell (SSH) library for .NET. The vulnerability allows a malicious SCP server to create or overwrite files on the client system due to improper containment validation of file and directory names returned by the remote SCP server. This issue affects SSH.NET versions 2025.1.0 and earlier, and is fixed in version 2026.0.0. Defenders should [truncated]