CyberRota Analysis
AI-GeneratedOpenSSH versions prior to 10.4 have a vulnerability in the SFTP component that allows an attacker to manipulate the file download location when using the command "sftp server:/path .". This could lead to unauthorized file access or overwriting of files on the client system, posing a risk to users who rely on SFTP for secure file transfers. Organizations utilizing OpenSSH for SFTP should prioritize updating to version 10.4 or later to mitigate this risk.
CVE
CVE-2026-59995
Severity
MEDIUM
CVSS
4.2
EPSS
0.25%
Original NVD Description
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
Related CVEs
Other vulnerabilities affecting the same vendor(s)