SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oProxyCommand=CMD]:/path and find_base_path() removes the brackets, leaving a host value that begins with - and is passed directly to ssh as a command-line argument. When a caller also supplies a path-valued sftp_server, ssh treats the normalized host as an option and the server path as its destination, causing an injected ProxyCommand to execute locally before any connection or authentication succeeds. The attack requires a caller or wrapper that passes an attacker-controlled mount source to SSHFS with the required sftp_server configuration and results in arbitrary command execution as the user running SSHFS. This issue is fixed in version 3.7.6.
CVE-2026-48711
This high-severity CVE scores 7.0 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.2%, top 90% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.0
- EG Score
- 7.0(medium)
- EG Risk
- 48(Track*)EG Risk 48/100SSVC: Track*
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity70% × 45%Exploitation40% × 40%Automatability0% × 15%Action: Watch closely — could escalate to Attend. - EPSS PROB
- 0%
- EPSS %ILE
- 10%
- KEV
- Not listed
Published
August 19, 2026
Last Modified
August 20, 2026
Advisory Details (4)
Auto-updated Aug 19, 2026SSHFS 3.7.6
Patch available: libfuse/sshfs sshfs-3.7.6
https://github.com/libfuse/sshfs/releases/tag/sshfs-3.7.6commit 29bb565ea640 (libfuse/sshfs)
Patch available: libfuse/sshfs sshfs-3.7.6 (contains commit 29bb565ea640)
https://github.com/libfuse/sshfs/commit/29bb565ea6405e2dd5a0ea65fe64da117e76055ereject hostname option injection via bracketed mount source
Patch available: libfuse/sshfs sshfs-3.7.6 (PR #362 merged 2026-05-29)
https://github.com/libfuse/sshfs/pull/362Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in sshfs · Advisory · libfuse/sshfs · GitHub
https://github.com/libfuse/sshfs/security/advisories/GHSA-mm85-q63v-4476Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 10× in last 7d / 23× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-08-30 01:56 UTCEG score recompute
- 2026-08-30 01:22 UTCEPSS rescore
- 2026-08-29 01:57 UTCEG score recompute
- 2026-08-28 21:41 UTCEPSS rescore
- 2026-08-27 19:12 UTCEG score recompute
- 2026-08-27 14:25 UTCEPSS rescore
- 2026-08-26 18:55 UTCEG score recompute
- 2026-08-26 14:46 UTCEPSS rescore
- 2026-08-24 19:04 UTCEG score recompute
- 2026-08-23 07:09 UTCEG score recompute
- 2026-08-23 00:19 UTCEPSS rescore
- 2026-08-22 07:13 UTCEG score recompute
- 2026-08-21 23:49 UTCEPSS rescore
- 2026-08-21 07:17 UTCEG score recompute
- 2026-08-20 22:55 UTCEPSS rescore
- 2026-08-20 19:18 UTCEG score recompute
- 2026-08-20 18:32 UTCEG score recompute
- 2026-08-20 16:17 UTCEG score recompute
- 2026-08-20 04:19 UTCEG score recompute
- 2026-08-20 04:08 UTCEG score recompute
- 2026-08-19 15:24 UTCEG score recompute
- 2026-08-19 14:57 UTCEG score recompute
- 2026-08-19 14:57 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Same CWE
10 shownCWE-88
- CVE-2007-0882EG 10.0EPSS p100HIGH
- CVE-2004-0480EG 10.0EPSS p95HIGH
- CVE-1999-0113EG 10.0EPSS p97HIGH
- CVE-2018-3856EG 9.9CRITICAL
- CVE-2020-28026EG 9.8EPSS p95CRITICAL
- CVE-2020-21224EG 9.8EPSS p99CRITICAL
- CVE-2020-25494EG 9.8EPSS p99CRITICAL
- CVE-2020-15692EG 9.8EPSS p90CRITICAL
- CVE-2020-12641EG 9.8 KEVEPSS p100CRITICAL
- CVE-2019-12148EG 9.8CRITICAL
Frequently asked(5)
What is CVE-2026-48711?
When was CVE-2026-48711 disclosed?
Is CVE-2026-48711 actively exploited?
What is the CVSS score of CVE-2026-48711?
How do I remediate CVE-2026-48711?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-48711
Is Your Infrastructure Affected by CVE-2026-48711?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.