CVE-2026-48798 | sshnet SSH.NET up to 2025.1.0 ScpClient ScpClient.Download directoryName/directoryInfo path traversal

SecurityVulns

A vulnerability was found in sshnet SSH.NET up to 2025.1.0. It has been rated as critical. The affected element is the function ScpClient.Download of the component ScpClient. The manipulation of the argument directoryName/directoryInfo leads to path traversal.

This vulnerability is uniquely identified as CVE-2026-48798. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More