GHSA-qm9r-w65j-rh8mHighCVSS 6.5

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add()...

Published
September 13, 2026
Last Modified
September 13, 2026

🔗 CVE IDs covered (1)

📋 Description

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access revocation.

🔗 References (7)