CVE-2026-47829
CloudFoundry Foundation bosh-cli, bosh cli
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli versions prior to v7.10.4.
- CVSS
- 7.7
- EPSS
- 0.22% 13.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.09