Executive brief
Apache MINA SSHD is a software library used by Java applications to provide secure file transfer (SSH/SCP) capabilities. A vulnerability in the file-receiving component allows a malicious sender to bypass intended folder restrictions. This could result in an attacker overwriting sensitive system files or placing malicious files in unauthorized locations on the server.
Technical details
A path traversal vulnerability exists in the sshd-scp component of Apache MINA SSHD due to insufficient validation of filenames in SCP 'C' (create) and 'D' (directory) commands. When an application is configured to receive files via SCP, a remote attacker can provide filenames containing path traversal sequences (e.g., ../). This allows the attacker to write files to arbitrary locations outside of the intended destination directory on the filesystem. The issue affects versions prior to 2.19.0 and 3.0.0-M5 specifically when the sshd-scp module is utilized.
Affected products
- Apache Software Foundation MINA SSHD < 2.19.0, 3.0.0-M1 to 3.0.0-M4
Timeline
- 2026-07-20: advisory: NVD publication date
- 2026-07-20: disclosed