CVE-2026-93995 Apache MINA SSHD sshd-git 输入验证不当漏洞
影响已认证攻击者可在服务器上写入任意文件
Apache MINA SSHD 的 sshd-git 组件通过 GitPgmCommandFactory 允许已认证的 SSH 客户端远程执行 git 命令。此前针对 CVE-2026-58624 的修复限制了可执行的 git 命令,但遗漏了 git archive 命令的单参数 -o=file.zip 形式,导致输入验证仍不充分。
影响范围
Apache MINA SSHD 2.19.0 及以下版本,以及 3.0.0-M1 至 3.0.0-M5 版本。
漏洞详情
漏洞属于输入验证不当。sshd-git 组件在限制 git archive 命令时,仅过滤了 --output 和 -o 选项,却未处理等号形式的单参数 -o=file.zip。已认证的 SSH 客户端可借此让服务器将归档文件写入服务器本地任意路径,而非返回给客户端。
利用条件与风险
利用前提是攻击者需通过 SSH 认证并具备执行 git 命令的权限。实战中可导致服务器文件被任意写入,可能进一步被利用进行提权或持久化。
修复建议
官方建议升级至 2.20.0 或 3.0.0-M6 版本。临时缓解措施暂无公开信息。
Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache
MINA SSHD is a Java library for client-side and server-side SSH.
Component org.apache.sshd:sshd-git provides though class GitPgmCommandFactory a way to configure an Apache MINA SSHD server such
that authenticated SSH clients can remotely execute git commands via the JGit library
on git repositories stored on the server. In CVE-2026-58624 this mechanism was restricted to only a few git commands, including “git archive” without “–output” or “-o” options such that the resulting archive would not be written on the server but instead sent back to the client over the SSH connection.
The fix done for CVE-2026-58624 was insufficient as it missed removing the single-argument “-o=file.zip” version of the command parameter from the “archive” command.
Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue.