Am I affected?
This record states its affected versions in a form that can't be compared automatically.
Description
This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and program routines ssh_sftpd:is_within_root/2.
The SFTP server uses string prefix matching via lists:prefix/2 rather than proper path component validation when checking if a path is within the configured root directory. This allows authenticated users to access sibling directories that share a common name prefix with the configured root directory. For example, if root is set to /home/user1, paths like /home/user10 or /home/user1_backup would incorrectly be considered within the root.
This issue affects OTP from OTP 17.0 before OTP 28.4.1, OTP 27.3.4.9 and OTP 26.2.5.18, corresponding to ssh from 3.0.1 before 5.5.1, 5.2.11.6 and 5.1.4.14.
Weaknesses & attack patterns
Weakness
CWE-22
·
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
in catalog →
MITRE ↗
Attack patterns
CAPEC-126
·
Path Traversal
MITRE ↗
Affected — Erlang / ssh Repository ↗
modules · source files · routines
Affected — GitHub / erlang/otp Repository ↗
modules · source files · routines
Workarounds
- Use OS-level chroot to run the Erlang VM/SFTP server process in an isolated filesystem environment.
- Ensure that no sensitive or precious data is readable or writable by the OS user running the Erlang VM.
- Ensure that the SFTP server port is not reachable from untrusted machines.
- Use directory naming conventions that avoid common prefixes (e.g., /home/users/alice/ instead of /home/user1/).
Configurations
References
GHSA-4749-w85x-hw9h ↗
vendor-advisory
EEF-CVE-2026-23942 ↗
related
Credits
CVSS breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N