A shell command injection vulnerability tracked as CVE-2026-5917 affects libgit2 versions 0.27.0 through 1.9.0 when the library is built with the libssh2 SSH backend using USE_SSH=libssh2. The flaw is in the gen_proto() function in ssh_libssh2.c, which inserts a repository path into a shell command without escaping shell metacharacters before passing it to libssh2_channel_exec(). The issue is classified as CWE-78 and carries a CVSS v3.1 score vector of AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H.
Attackers can exploit the bug by supplying a malicious repository path containing characters such as quotes, semicolons, or pipes, including through a crafted submodule URL in a .gitmodules file during a recursive clone. If triggered, the SSH server's shell may execute attacker-injected commands under the victim's SSH user account, creating a path to full compromise of confidentiality, integrity, and availability in affected environments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-5917 states that the new CVE was received by disclosure@vulncheck.com on August 11, 2026. The entry identifies the issue as a shell command injection in libgit2's ssh_libssh2 backend affecting versions 0.27.0 through 1.9.0.
VulnCheck disclosed a shell command injection vulnerability affecting libgit2 versions 0.27.0 through 1.9.0 when built with the libssh2 SSH backend. The advisory described the root cause in ssh_libssh2.c and noted exploitation via malicious repository paths or crafted submodule URLs during recursive clone operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.