CVE-2026-47829

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
09/07/2026
Last modified:
13/07/2026

Description

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator&amp;#39;s workstation.<br /> Affected versions: bosh-cli versions prior to v7.10.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudfoundry:bosh_cli:*:*:*:*:*:*:*:* 7.10.4 (excluding)