From 1b39f39657d2e58f8ec57341581a39bbf0be645b Mon Sep 17 00:00:00 2001 From: "djm@openbsd.org" Date: Mon, 29 Jun 2026 01:47:21 +0000 Subject: [PATCH] upstream: avoid download to server-controlled path when performing download on the commandline. From Swival scanner OpenBSD-Commit-ID: d1b2c44305fdfe6d51eed9ecc727e59478bf311f CVE: CVE-2026-59995 Upstream: https://github.com/openssh/openssh-portable/commit/1b39f39657d2e58f8ec57341581a39bbf0be645b Signed-off-by: Thomas Perale --- sftp.c | 11 +++-------- 1 file changed, 3 insertions(+), 8 deletions(-) diff --git a/sftp.c b/sftp.c index 0ab9206c2772..0b57e083398c 100644 --- a/sftp.c +++ b/sftp.c @@ -2270,13 +2270,8 @@ interactive_loop(struct sftp_conn *conn, char *file1, char *file2) return (-1); } } else { - /* XXX this is wrong wrt quoting */ - snprintf(cmd, sizeof cmd, "get%s %s%s%s", - global_aflag ? " -a" : "", dir, - file2 == NULL ? "" : " ", - file2 == NULL ? "" : file2); - err = parse_dispatch_command(conn, cmd, - &remote_path, startdir, 1, 0); + err = process_get(conn, dir, file2, remote_path, 0, 0, + global_aflag, 0); free(dir); free(startdir); free(remote_path);