| id: GO-2026-5009 | |
| modules: | |
| - module: github.com/kopia/kopia | |
| versions: | |
| - fixed: 0.23.0 | |
| vulnerable_at: 0.22.3 | |
| summary: 'Kopia: RCE via SSH ProxyCommand Injection in github.com/kopia/kopia' | |
| cves: | |
| - CVE-2026-45695 | |
| ghsas: | |
| - GHSA-2q4c-3mrw-63c3 | |
| references: | |
| - advisory: https://github.com/kopia/kopia/security/advisories/GHSA-2q4c-3mrw-63c3 | |
| - fix: https://github.com/kopia/kopia/pull/5354 | |
| source: | |
| id: GHSA-2q4c-3mrw-63c3 | |
| created: 2026-05-20T12:41:25.112574238-04:00 | |
| review_status: UNREVIEWED |