Cloud Foundry BOSH CLI Shell Injection Vulnerability

Vulnerability

A shell injection vulnerability has been identified in Cloud Foundry BOSH CLI versions prior to 7.10.5. This vulnerability allows a compromised or malicious BOSH Director to execute arbitrary shell commands on the operator's workstation. The issue arises when the operator uses the 'bosh ssh', 'bosh scp', or 'bosh logs -f' commands with default flags.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of shell commands on the operator's workstation, potentially allowing for further manipulation or compromise of the system.

Remediation

Users are advised to upgrade BOSH CLI to version 7.10.5 or later.

Added: Jul 9, 2026, 6:25 AM
Updated: Jul 9, 2026, 6:25 AM

Vulnerability Rating

Custom Algorithm
spread
1.2
impact
2.5
exploitability
3.6
remediation
7.7
relevance
9.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.