Intel

AIKIDO-2026-742200

net-ssh is vulnerable to Authorization Bypass

Authorization BypassGHSA-qpg5-fx6p-8cq3 Published Yesterday

80

High Risk

This Affects:

RUBYnet-ssh
0.0.1 - 7.3.4
Fixed in 7.3.5
Are you affected? Scan for Free

TL;DR

Net::SSH::Service::Forward#initialize registers auth-agent and auth-agent@openssh.com channel handlers inside on_open_channel even when forward_agent is not enabled. A server the client connects to can open an inbound channel and reach the client's local SSH agent through auth_agent_channel when the client requests port forwarding, even if agent forwarding was never enabled. The fix registers those handlers only when the client has enabled agent forwarding.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use SSH port forwarding on a connection to a server you do not fully control.

Background info

net-ssh is vulnerable to Authorization Bypass in versions 0.0.1 - 7.3.4.

How to fix this

Upgrade the net-ssh library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform