GPU VulnDB

Database/Kernel, userspace & hypervisor

OpenSSH sftp: malicious server can write files outside the target directory during recursive copy

CVSS 4.2CVE-2026-106552Kernel, userspace & hypervisorcurated

Impact

In sftp before 10.6 a server controls path elements that the client trusts during a recursive copy, so files can land outside the directory the operator chose. The exposure in a datacenter is automation that pulls artifacts over sftp - model weights, dataset shards, firmware bundles, backup restores - often running as a privileged service account on a management or build host. A traversal write under that account can overwrite scripts or configuration that later run on the fleet. The record rates it integrity and availability only, high attack complexity, and it requires the operator to initiate a recursive copy from a server the attacker controls.

Who can reach it

A malicious or compromised sftp server, acting against a client that starts a recursive copy from it. No authentication to the client is needed; user interaction (running the copy) is.

What to do

Upgrade the OpenSSH client package to 10.6 or a distribution backport. No daemon or node restart is required - the fix lands in the sftp binary and applies to the next copy. Until then, run recursive sftp pulls from untrusted endpoints only under an unprivileged account in a throwaway directory.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.