{"id":"CVE-2026-70615","summary":"boringproxy 0.10.0 SSH authorized_keys Injection via Tunnel Creation","details":"boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorized_keys to gain persistent shell access, and subsequently read cleartext credentials from the database file including all user tokens, tunnel private keys, and TLS certificates.","modified":"2026-08-08T03:30:50.286459975Z","published":"2026-08-05T19:34:13.322Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-93"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70615.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70615.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70615"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/boringproxy-ssh-authorized-keys-injection-via-tunnel-creation"},{"type":"PACKAGE","url":"https://github.com/boringproxy/boringproxy"},{"type":"EVIDENCE","url":"https://github.com/theopaid/Remote-Code-Execution-And-Privilege-Escalation-Through-SSH-Authorized-Keys-Injection-boringproxy-/blob/master/README.md"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/boringproxy/boringproxy","events":[{"introduced":"0"},{"last_affected":"658a8841d78c0f891f288d52434f4d2a66378686"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.10.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v0.10.0","v0.9.1","v0.9.0","v0.8.2","v0.8.1","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.0","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70615.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H"}]}