
I discovered CVE-2026-50523, a command injection vulnerability in PowerShell SSH remoting on Linux/macOS. A crafted -UserName value can break argument boundaries and inject OpenSSH options such as ProxyCommand, leading to local command execution on the client. https://t.co/zwf30VAxPl
Post summary
The author announces discovery of CVE‑2026‑50523, a command‑injection flaw in PowerShell SSH remoting that permits local command execution via crafted -UserName values; no PoC, exploit, or patch information is included.

