CVE-2026-47829EPSS p34.1%
CVE-2026-47829CVE-2026-47829
cloudfoundry / bosh_cli
Description
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation.
Affected versions: bosh-cli versions prior to v7.10.4.
Scoring
| CVSS | 7.8 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 0.42% probability of exploitation · percentile 34.1% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-13 |