Microsoft Security Response Center 中文 关注 在 OpenSSH 10.4 之前版本中,当使用"attacker-controlled server"配合"sftp server:/path ."命令时,SFTP 未能正确限制下载文件的位置,存在 CVE-2026-59995 漏洞。 CVE-2026-59995 sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. msrc.microsoft.com