CVE-2026-47829
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh proces… (CVE-2026-47829)
highEPSS 0.4%
Description
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli versions prior to v7.10.4.
Metrics
Severity
high
87.53
no public PoC known
8.3
7.7
Published
2026-07-09 06:25 UTC
—
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
cloudfoundry
bosh_cli7.10.4
References & sources
IDCVE-2026-47829