CloudFoundry Foundation Vulnerabilities and Affected Products
Vulnerabilities associated with bosh-cli.
Products
Clear product- CF Deployment2 vulnerabilities
- UAA2 vulnerabilities
- BOSH1 vulnerability
- BOSH CLI tool1 vulnerability
- bosh-cli1 vulnerability
- Cf-deployment1 vulnerability
- Routing release1 vulnerability
- smb-volume-release1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-47829HIGH | Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised DirectorArgument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli versions prior to v7.10.4. CWE-88Jul 9, 2026 | CVSS7.7v4.0 | EPSS0.225% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |