CVE-2016-5725: Jcraft Jsch
Medium severity, CVSS 5.9. EPSS: 24.1% chance of exploitation in the next 30 days.
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
Affected products
- Jcraft Jsch: up to and including 0.1.53
Published 2017-01-19. Last modified 2026-06-17.