Executive brief
Apache MINA SSHD is a Java library used to build SSH servers and clients. A security flaw in its Git integration component allows authenticated users to execute unauthorized Git commands on the server. This could allow an attacker to write files to arbitrary locations on the server's filesystem, potentially leading to system instability or unauthorized data modification.
Technical details
An improper input validation vulnerability exists in the 'sshd-git' component of Apache MINA SSHD within the GitPgmCommandFactory. When a server is configured to allow remote Git command execution via JGit, the factory fails to properly restrict the commands available to authenticated SSH users. An attacker can leverage commands such as 'git archive' with the '--output' argument to write files to arbitrary locations on the server's filesystem. The vulnerability is exploitable by any user with valid SSH credentials if the GitPgmCommandFactory is active. The fix involves implementing a whitelist of safe commands and ignoring the '--output' argument for 'git archive' to ensure data is only returned via the SSH channel.
Affected products
- Apache Software Foundation Apache MINA SSHD 2.0.0 to 2.18.0, 3.0.0-M1 to 3.0.0-M4
Timeline
- 2026-07-20: advisory: CVE published by Apache Software Foundation