Junglewise Threat Intelligence

CVE-2026-45695: Kopia RCE via SSH ProxyCommand injection in HTTP API

CVE-2026-45695 · Severity: critical · CVSS 9.8 · Published 2026-07-16

Technologies: github.com/kopia/kopia (Go). Vendors: Go.

Executive brief

Kopia is a backup tool used to secure and manage data across various operating systems. A security flaw in its web-based management interface allows an unauthenticated attacker to execute arbitrary commands on the host system. This could lead to a total system takeover, data theft, or the destruction of backups. The vulnerability is particularly dangerous when the server is configured to run without a password and is accessible over a network.

Technical details

A remote code execution (RCE) vulnerability exists in Kopia's HTTP server due to missing authentication and improper input validation. When started with the '--without-password' flag, the server allows unauthenticated access to the '/api/v1/repo/exists' endpoint. An attacker can submit a crafted JSON request containing an SFTP storage configuration with 'externalSSH: true' and malicious 'sshArguments'. Specifically, by injecting '-oProxyCommand=<cmd>', the attacker leverages OpenSSH's behavior to execute arbitrary shell commands via 'exec.CommandContext'. This occurs because the application splits arguments only on spaces without proper sanitization or shell-style tokenization. The issue is fixed in version 0.23.0, which restricts unauthenticated servers to loopback interfaces by default.

Affected products

  • Kopia Kopia <= 0.22.3

Timeline

  • 2026-05-05: patched: Initial fix commit and pull request submitted
  • 2026-05-12: other: Version 0.23.0 released
  • 2026-05-13: advisory: GitHub Security Advisory published
  • 2026-07-16: disclosed: CVE published to NVD

References

Related threats