Showing 1 vulnerability on this page for bosh-cli

Signals CISA KEV Ransomware Nuclei
CloudFoundry Foundation vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli versions prior to v7.10.4.

CWE-88Jul 9, 2026
CVSS7.7v4.0EPSS0.225%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX