Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-5725

44
FAUCET Score

CVE-2016-5725 describes a directory traversal vulnerability in JCraft JSch versions prior to 0.1.54, specifically impacting Windows systems when using the ChannelSftp.OVERWRITE mode. This flaw allows a malicious SFTP server to write arbitrary files on a client's system by including "..\" sequences in responses to recursive GET commands. The vulnerability has a CVSS v3 score of 5.9 (Medium), indicating a network-based attack with high impact on integrity, but requiring high attack complexity. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-40411) exists, suggesting public exploit code availability, though there is no evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.1.53CPE matchmatch criteria
cpe:2.3:a:jcraft:jsch:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.9MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
24.14%
Probability of exploitation in next 30 days
EPSS Percentile
97.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
ExploitDB: EDB-40411 · Sep 22, 2016
This CVE's current EPSS score of 0.2414 is in the 98th percentile among its peer group of 19,953 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

mavenpatch availablevia ghsa
Product: com.jcraft:jschFixed in: 0.1.54
redhatpatch availablevia redhat_api
Product: Red Hat JBoss A-MQ 6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Fuse 6.3
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift Enterprise 2Fixed in: jsch
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: jsch
redhatno patchvia redhat_api
Product: Red Hat Virtualization 4Fixed in: jsch
redhatend of lifevia redhat_api
Product: Red Hat JBoss A-MQ 6Fixed in: jsch
redhatend of lifevia redhat_api
Product: Red Hat JBoss BRMS 6Fixed in: jsch
redhatend of lifevia redhat_api
Product: Red Hat JBoss Data Virtualization 6Fixed in: jsch
redhatend of lifevia redhat_api
Product: Red Hat JBoss Fuse 6Fixed in: jsch
redhatend of lifevia redhat_api
Product: Red Hat JBoss Fuse Service Works 6Fixed in: jsch
redhatend of lifevia redhat_api
Product: Red Hat BPM Suite 6Fixed in: jsch

Vendor Advisories (2)

mavenGHSA-q446-82vq-w674medium

Improper Limitation of a Pathname to a Restricted Directory in JCraft JSch

May 13, 2022
redhatCVE-2016-5725Moderate

jsch: ChannelSftp path traversal vulnerability

Aug 31, 2016

References

packetstormsecurity.com / files/138809/jsch-0.1.53-Path-Traversal.html
Third Party AdvisoryVDB Entry
access.redhat.com / errata/RHSA-2017:3115
seclists.org / fulldisclosure/2016/Sep/53
Mailing ListThird Party Advisory
github.com / tintinweb/pub/tree/master/pocs/cve-2016-5725
Third Party Advisory
lists.debian.org / debian-lts-announce/2020/04/msg00017.html
exploit-db.com / exploits/40411
Third Party AdvisoryVDB Entry
oracle.com / security-alerts/cpuApr2021.html
oracle.com / security-alerts/cpujan2021.html
oracle.com / security-alerts/cpuoct2020.html
jcraft.com / jsch/ChangeLog
Release Notes
securityfocus.com / bid/93100
Third Party AdvisoryVDB Entry