Improper Encoding or Escaping of Output Affecting github.com/go-git/go-git/plumbing/transport/ssh package, versions <5.19.1>=6.0.0-alpha.1 <6.0.0-alpha.4


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.37% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMGOGITGOGITPLUMBINGTRANSPORTSSH-16776517
  • published20 May 2026
  • disclosed19 May 2026
  • creditN0zoM1z0

Introduced: 19 May 2026

CVE-2026-45570  (opens in a new tab)
CWE-116  (opens in a new tab)

How to fix?

Upgrade github.com/go-git/go-git/plumbing/transport/ssh to version 5.19.1, 6.0.0-alpha.4 or higher.

Overview

Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output due to improper escaping of single quotes in the SSH transport command construction process. An attacker can inject arbitrary shell tokens by including single quotes in the repository path, potentially leading to unintended command execution on SSH servers that evaluate the exec command through a shell.

CVSS Base Scores

version 4.0
version 3.1