Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-70

JLSEC-2026-70

JLSEC Published
Modified
Affected Packages
OpenSSH_jll < 9.9.1+0
Aliases / Upstream
CVE-2023-51385

In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.

References