Junglewise Threat Intelligence

CVE-2026-59995: OpenBSD OpenSSH path traversal in sftp client

CVE-2026-59995 · Severity: medium · CVSS 4.2 · Published 2026-07-08

Technologies: OpenBSD Openssh. Vendors: OpenBSD.

Executive brief

OpenSSH is a widely used suite of secure networking utilities for remote login and file transfer. A vulnerability in the SFTP client allows a malicious server to trick a user into downloading files to an incorrect location on their computer. This could lead to important files being overwritten or the placement of malicious files in sensitive directories if a user connects to a compromised or untrusted server.

Technical details

A relative path traversal vulnerability (CWE-23) exists in the OpenSSH sftp client when using the command-line syntax 'sftp server:/path .'. The client fails to properly constrain the download location, allowing an attacker-controlled server to influence the local destination path. An attacker can exploit this by hosting a malicious SFTP server and enticing a user to connect and perform a download, resulting in files being written outside the intended directory. This issue is resolved in OpenSSH version 10.4.

Affected products

  • OpenBSD OpenSSH before 10.4

Timeline

  • 2026-07-06: patched: OpenSSH 10.4 released with security fixes.
  • 2026-07-08: disclosed: CVE-2026-59995 published.

References

Related threats