Executive brief
A vulnerability in the OpenSSH scp utility could allow a malicious server to write files to unintended locations on a user's system. When a user performs a remote-to-remote file copy, a compromised server could redirect the file to a parent directory instead of the specified target. This could lead to unauthorized file placement or the overwriting of important data if a user is tricked into connecting to a malicious host.
Technical details
A relative path traversal vulnerability (CWE-23) exists in the scp client of OpenSSH versions prior to 10.4. The flaw occurs during remote-to-remote file transfers where the client fails to sufficiently validate the destination path provided by the server. A malicious or compromised remote server can exploit this by sending a file that is placed in the parent directory of the intended target. Exploitation requires a user to initiate a copy between two remote destinations, one of which is controlled by the attacker. The issue is addressed in OpenSSH 10.4.
Affected products
- OpenBSD OpenSSH before 10.4
Timeline
- 2026-07-06: patched: OpenSSH 10.4 released with a fix.
- 2026-07-08: advisory: CVE-2026-59996 published.