CVE-2026-59995 UNKNOWN

CVE-2026-59995

Published: 2026-07-08

Description

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…