Executive brief
A vulnerability exists in the Apache MINA SSHD library's Git integration component, which is used to manage Git repositories over SSH. An authenticated user could bypass directory restrictions to access or modify Git repositories they are not authorized to see. This could lead to the exposure of sensitive source code or unauthorized changes to software projects.
Technical details
A path traversal vulnerability (CWE-22) exists in the sshd-git bundle of Apache MINA SSHD due to insufficient path validation in Git operations such as git-upload-pack and git-receive-pack. An attacker authenticated over SSH can provide manipulated paths to escape the configured Git server root directory. This allows for unauthorized read and limited write access to repositories on the host file system. The issue is resolved in versions 2.18.0 and 3.0.0-M4.
Affected products
- Apache MINA SSHD (sshd-git) 2.0.0 to 2.17.1, 3.0.0-M1 to 3.0.0-M3
Timeline
- 2026-05-30: disclosed: Initial disclosure on oss-security mailing list
- 2026-06-01: advisory: GitHub and NVD advisories published