{"id":"CVE-2020-26301","aliases":["GHSA-652h-xwhf-q4h6"],"url":"https://o3.security/vulnerability/CVE-2020-26301","summary":"OS Command Injection in ssh2","details":"ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This is fixed in version 1.4.0.","published":"2021-09-20T20:15:11.513Z","modified":"2026-07-09T00:37:09.691809Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.03832,"percentile":0.89328,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"ssh2","fixedVersion":"1.4.0"}],"fix":{"url":"https://github.com/mscdex/ssh2/commit/f763271f41320e71d5cbee02ea5bc6a2ded3ca21","label":"mscdex/ssh2@f763271"},"references":[{"type":"ADVISORY","url":"https://www.npmjs.com/package/ssh2"},{"type":"FIX","url":"https://github.com/mscdex/ssh2/commit/f763271f41320e71d5cbee02ea5bc6a2ded3ca21"},{"type":"FIX","url":"https://securitylab.github.com/advisories/GHSL-2020-123-mscdex-ssh2/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:37:09.691809Z"}}