CVE-2026-47829
EUVD-2026-4251509.07.2026, 07:16
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli versions prior to v7.10.4.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cloudfoundry | bosh_cli | 𝑥 < 7.10.4 |
𝑥
= Vulnerable software versions