Cloud Foundry BOSH CLI Argument Injection Vulnerability Allows Local Command Execution

Vulnerability

A vulnerability exists in BOSH CLI versions prior to 7.10.4, allowing a compromised BOSH Director to inject arbitrary OpenSSH options into the local SSH process. This occurs when an operator uses non-interactive SSH commands, such as 'bosh ssh -c' or 'bosh logs -f'. The injected options can lead to unauthorized command execution on the operator's workstation.

Impact

Exploitation of this vulnerability could result in unauthorized local command execution on the operator's workstation.

Remediation

Users are advised to upgrade to BOSH CLI version 7.10.4 or later.

Added: Jul 9, 2026, 7:24 AM
Updated: Jul 9, 2026, 7:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.8
remediation
0.0
relevance
9.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.