CVE-2026-5917 is a shell command injection vulnerability in libgit2 builds configured to use the libssh2 SSH backend. In ssh_libssh2.c, gen_proto() incorporates the remote repository path into a command string without escaping shell metacharacters before sending that command through libssh2_channel_exec(). A repository path containing shell syntax can therefore alter the command interpreted by the remote SSH server. A malicious repository can embed such a path in a submodule URL, causing injection when a user performs a recursive clone. Affected versions are releases before 1.8.7 and 1.9.x releases before 1.9.7 when built with USE_SSH=libssh2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-impact vulnerability affecting cargo-c packages on Amazon Linux 2023. It is network-accessible, requires low attack complexity and no privileges, but requires user interaction; successful exploitation can result in high confidentiality, integrity, and availability impact.
A shell-command-injection vulnerability in libgit2's libssh2 SSH backend. Repository paths containing unescaped shell metacharacters can lead to arbitrary command execution on an SSH server when a malicious submodule is processed during recursive cloning.
A libgit2 vulnerability covered by Debian advisory DSA-6453 affecting Debian 13/libgit2 packages; the advisory states the issues could lead to arbitrary command execution on a remote SSH server, credential disclosure, denial of service, or directory creation outside a repository working tree.
An arbitrary code execution vulnerability in libgit2 caused by shell command injection in the SSH backend.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.